A data breach at a community bank exposes the personal financial information of more than 50,000 customers. Within 60 days, three things happen at once.
-
A group of shareholders files a derivative action in state court. The allegation: the board of directors failed to maintain adequate cybersecurity oversight. This is what courts call a Caremark claim, the legal theory that directors can be held personally liable for failing to monitor known compliance risks.
-
The OCC opens a formal examination of the bank’s cybersecurity program. The 36-hour notification went out on time, but the examination will dig into whether the board approved the information security program, whether it reviewed management reports, and whether it provided what the FFIEC calls “credible challenge to management.” Legal fees will run six figures at minimum.
-
A class action is filed on behalf of affected customers, alleging the bank failed to protect their personal information.
The bank’s directors turn to their directors and officers (D&O) policy. They have had D&O coverage for years. It is supposed to protect them from exactly this kind of claim.
The D&O Policy Steps Out
The D&O carrier reviews the claims and points to the policy’s cyber exclusion: “arising out of any cyber event.” The derivative action, the regulatory defense costs, the shareholder claims. All of them arise from the data breach. All of them are excluded.
So the directors ask the obvious next question. Will the cyber policy cover us?
Partly, and more than most boards expect. Turn to the definitions section, not the coverage grants, and look up Insured. On every community bank cyber form I have read in full, directors are named there. One defines an insured person to include any “director, officer, member of the board of trustees, governor, advisory or honorary director.” Another says “any director or officer of the Insured Organization.” A third reaches “any past, present or future officer, director, trustee.” The directors have standing. Their defense costs in that OCC examination are a covered loss.
That is the good news, and it took a 37-year consultant telling me I was wrong to find it. The coverage grants describe events. The definitions decide who. Read only the first half and you will reach a confident wrong answer, which is what I did.
The fidelity bond is not applicable. This is not fraud, theft, or employee dishonesty.
What survives is narrower and more mechanical. Three things.
The limit is shared and it is spent in order. A cyber policy has no Side A. D&O programs are built with a tower reserved for individuals precisely because the entity can exhaust everything else. Cyber policies are not. The directors sit on the same limit that pays forensics, notification, credit monitoring and business interruption, and those costs land in the first sixty days. The board investigation arrives in month six. This is arithmetic, not interpretation.
On some forms the clock starts late. One of the three forms only recognizes a claim once a formal proceeding is “commenced by the filing of a notice of charges, formal investigative order or similar document.” The other two reach a plain request for information. Most of what a bank board actually faces begins well before anything formal: matters requiring attention, examiner document requests, consent order negotiation. On the strictest form, none of that is a claim yet.
The derivative suit is the real seam. Here the original version of this post was half right. Cyber policies carry a securities exclusion, and its breadth varies enormously. One form defines a securities claim to include a common law action “pled in tandem with, or in lieu of” a securities violation, brought “directly or derivatively,” and then bars any loss that “in any way involves” such a claim. A Caremark suit alleging the board failed to oversee cybersecurity looks like it lands inside that. The other two forms are limited to securities transactions and securities law violations, with no derivative language at all. Same product, opposite answer.
The D&O side varies just as much, and this is the part I had wrong for longer. The cyber exclusion is not a single clause that behaves the same way everywhere. On two of the four D&O forms I have compared, the exclusion carries a carve-back that keeps the derivative suit alive. One says plainly that the exclusion “shall not apply to any director or officer,” which is unconditional. Another deletes privacy violations from the cyber exclusion altogether and then names security holder derivative claims in an express carve-back. On the other two forms there is no carve-back and the derivative suit is excluded.
Which means the seam only actually opens when both sides fail at once: a D&O cyber exclusion with no derivative carve-back, sitting next to a cyber policy whose securities exclusion is broad enough to reach a Caremark claim. That combination is real, and I have seen it. It is also not the default. Two doors have to be shut, and on most programs at least one of them is open.
Do not read that as reassurance, and do not read it as a reason to switch carriers. The forms that close the seam and the forms that leave it open are not sorted by carrier reputation or price, and a bank that moves to escape one bad clause can land on a form that is worse on both sides. This is a question you answer by reading the two policies you already have, not by shopping.
Three-Policy Breakdown
The policy built to protect directors steps out. The one that picks them up was not built for it.
For credit unions and mutual savings banks the picture is better, because the seam that matters most requires shareholders and they do not have any. There is no derivative suit, so the securities exclusion has nothing to bite on. What remains for a credit union board is NCUA supervision, member harm claims and privacy complaints, and those run through the cyber policy’s regulatory coverage with the directors named as insureds. The exposure is the shared limit and the trigger point, not the void.
This Is Not Just an Insurance Problem
The breach is the first-order event. The board getting sued is the second-order event. The D&O gap means the second-order event is funded, if at all, out of whatever the first-order event left behind.
But the deeper problem is governance. After a breach, regulators and shareholders do not just ask what happened. They ask who was responsible for preventing it. They ask whether the board received cybersecurity briefings, whether it assigned committee ownership, whether it tracked remediation, and whether management escalated known risks. If the board cannot show documented oversight, the breach becomes a governance failure.
About 45 percent of companies that experience a significant cyber event also face a D&O event: securities suits, regulatory actions, or derivative claims (WTW, 2024 FINEX Observer). Cyber has ranked among the top three concerns for directors and officers in WTW’s global D&O survey every year since 2020.
I review community bank insurance programs. Every D&O policy I have read carries a cyber exclusion. What differs is how far it reaches, and whether anything is carved back out of it, and that difference decides whether a board is exposed or merely inconvenienced. It is not a question you can answer from the declarations page.
For community bank board members, many of whom serve as a civic duty rather than as professional directors, the point is not that personal assets are certain to be at risk. It is that whether they are turns on two clauses in two policies that nobody at the table has read.
The Courts Are Watching
After a data breach exposed 339 million guest records, shareholders sued Marriott's board under the Caremark theory, alleging the directors failed to oversee cybersecurity. The Delaware Court of Chancery recognized cybersecurity as a serious board oversight concern, but dismissed the claim. Why? Because Marriott's board could show regular cybersecurity briefings, committee ownership, outside expert assessments, remediation tracking, and incident escalation to the board during the investigation. The court found the board had a functioning oversight structure. Most community bank boards cannot show any of these.
The FTC held Drizly's CEO personally responsible for cybersecurity failures after a breach exposed data on 2.5 million consumers. The order follows Rellas to any future company for 10 years: if he serves in a leadership role at a firm handling substantial consumer data, he must implement an information security program. This was the first time the FTC held a CEO personally accountable in a privacy and security enforcement action. It is an administrative order, not a court judgment, but the direction is clear. Cybersecurity accountability is personal, not just institutional.
The scale of exposure at larger institutions illustrates what is at stake. The Equifax breach produced more than $880 million in total settlements and penalties. Capital One faced an $80 million OCC penalty and a $190 million consumer class action from a single breach. The FDIC prohibits banks from insuring civil money penalties with D&O insurance. Defense costs may be coverable, but the penalties themselves are personal exposure.
No published court case exists where a community bank board was the defendant in a cybersecurity oversight claim. That does not mean the gap is not there. It means banks settle these quietly, or the claims have not arrived yet. The legal framework is set. The question is when, not if.
The Fix
The community bank in this scenario made two changes at its next renewal. It replaced its D&O policy with one that does not contain a blanket cyber exclusion, and it moved to a cyber form with a narrow securities exclusion and a claim trigger that reaches a request for information. It also established a documented cybersecurity oversight process at the board level.
One thing it did not do, and one thing an earlier version of this post suggested: ask the broker to add directors as additional insureds on the cyber policy. On these forms they are already insureds. The request buys nothing and tells your broker you did not read the policy.
Four things to check now:
You cannot close a gap you have not checked.
Board liability is one of five incident types where coverage breaks down across all three policies. I map the full picture in Five Common Cyber Incidents, Three Policies, and the Gaps Between Them.
For banks in New York, this gap has a regulatory enforcement dimension. NYDFS has collected $63 million in penalties under 23 NYCRR 500, and the same D&O cyber exclusion blocks coverage for the investigative costs that follow. I covered this in What 23 NYCRR 500 Means for Your Bank’s Insurance.
Find out whether your D&O cyber exclusion reaches a post-breach derivative claim, and whether any Side A layer sits behind it. Get in touch.