Six Months After a Breach, Your Credit Union's Cyber Policy Is Funding Three Fights Alone

I wrote recently about the coverage gaps that surface when you read a credit union’s cyber, bond, and D&O policies together. Entity-level D&O exclusions, wire fraud co-payments, vendor outage sublimits. This article is about what happens when those gaps arrive as claims.

They do not arrive all at once. They surface in sequence over the first six months after a breach. And each one compounds the last, because every gap that the D&O policy fails to cover pushes more weight onto the cyber policy.

By month six, the cyber policy is funding three separate fights from a single aggregate limit.

Coverage gaps surfacing over time.
Months 1-2
No investigation coverage
NCUA subpoenas before a formal proceeding have zero coverage
Months 3-6
Institution uninsured
Member lawsuit defense falls to the cyber policy, not the D&O
Month 6+
Wrong target
D&O carve-back protects individual directors, not the credit union itself

First Week: The Cyber Policy Does Its Job

A breach is discovered. The credit union notifies NCUA within 72 hours. The cyber policy activates: forensics, breach counsel, member notification. This part generally works. The cyber policy was built for it.

Months 1-2: The Investigation Moves to the Boardroom

NCUA begins its examination. It starts with the breach itself, but expands. Did the board approve the information security program? Did directors receive cybersecurity briefings? Did the board allocate adequate resources? The examination shifts from the IT team to the boardroom.

NCUA sends document requests. Board meeting minutes. Risk assessment evidence. Training records. The credit union needs counsel to respond, prepare board members for interviews, and assess regulatory exposure.

The D&O policy offered coverage for exactly this. A credit union-specific endorsement covered early-stage investigation costs. But it was not purchased. The declarations page read “No Coverage.”

The coverage was available for a modest additional premium. Without it, pre-formal NCUA subpoenas have zero coverage.

Months 3-6: The Member Lawsuit Lands on the Wrong Policy

Members whose data was exposed file a class action. They allege the board failed to protect their information, failed to oversee cybersecurity, failed to allocate resources. These are breach-of-fiduciary-duty claims, not securities claims.

The credit union turns to its D&O. The cyber exclusion denies coverage. At this credit union, the exclusion applied at the entity level: individual directors kept their personal coverage, but the institution itself had no D&O response for the member lawsuit.

The only option left is the cyber policy. But the cyber policy is already covering breach response, and at this credit union, it had defense costs inside limits. Every dollar spent on lawyers for the member lawsuit reduces what is left for forensics, notification, and regulatory defense. Breach response and lawsuit defense are now competing for the same pool of money.

Two fights. One policy. Defense costs inside limits means every dollar is a trade-off.

Month 6+: The Safety Valve Pointed at the Wrong Target

If NCUA finds the board’s cybersecurity oversight was deficient, the investigation becomes a formal enforcement action. Consent orders. Civil money penalties. Personal liability for individual directors.

The D&O does have a surviving carve-back. Individual directors and officers retain personal coverage despite the cyber exclusion. If a director faces personal liability, the D&O responds. That protection was real, and at this credit union it was the strongest individual coverage I have seen.

But the formal enforcement action is against the institution. The entity exclusion blocks that. The carve-back protects directors personally, but the institution gets nothing. The credit union is back on the cyber policy. The same cyber policy already covering breach response and already defending the member class action. Three fights, one aggregate limit.

The D&O's one surviving carve-back protects directors, not the credit union. The institution carries the weight alone.

The Compounding Problem

The D&O was supposed to share the load with the cyber policy. When it cannot, the cyber policy carries everything. The industry designed it to fill the D&O gap. That makes the compounding problem a feature of the architecture, not a mistake. It also makes the aggregate limit, the defense-cost structure, and the investigation endorsement the three things worth reading before renewal.

The individual director protections were strong. TruStage’s personal coverage for directors was the best I have seen. If a board member is worried about personal liability, the structure works. But the institution bears the full financial weight of six months of post-breach fallout from one policy that was not designed to carry it alone.

Three gaps, six months, one policy absorbing all of it. That is where the exposure sits.

This is the credit union-specific version of a problem that hits banks too. I wrote about the D&O cyber exclusion from the bank side, where the seam between D&O and cyber leaves directors with zero coverage after a breach.

If your board has never reviewed the D&O cyber exclusion, the investigation coverage election on the declarations page, and what happens when the cyber policy becomes the sole source of defense funding, those three things are worth reading before your next renewal.

Find out whether your D&O policy protects the institution after a cyber event, or just the individual directors. That is what a Risk Intelligence Report is for. Get in touch.
Joerg Proeve, Founder and Independent Risk Advisor
Joerg Proeve

Founder of Breezy Risk. 20 years of insurance, background in cybersecurity and engineering. Audits insurance for community banks and credit unions.

More about Joerg →