Skip To Content

Our Work

Cybersecurity Protection in Management Agreements

In light of the current dangers that private and confidential information contained in the digital files maintained by Cooperative associations, Condominiums, other housing associations and their managing agents may be hacked or otherwise illegally accessed, it is now recommended that the Cooperative and Condominium Boards require their management companies to obtain cyber liability insurance coverage (CLIC), with minimum limit of $1,000,000 to cover liability for a data breach in which personal information of employees, customers or vendors of Agent is exposed or stolen by a hacker or other unauthorized person who has gained access to the electronic network and data of Agent, with respect to records and data relating to the operations of Agent.

The cyber insurance policy covers Information Privacy Events and Network Security Events.

An Information Privacy Event in cyber security insurance is an unauthorized disclosure, access, loss, theft, or compromise of sensitive personal or confidential data that triggers policy coverage or third-party liability. The compromised data may involve Personally Identifiable Information (PII) like Social Security numbers, bank accounts, and health records (Protected Health Information or PHI), or confidential corporate and employee data. Liability can stem from malicious cyberattacks (hacking, malware) or non-technical failures (lost unencrypted laptops, improper disposal of paper files).

A network security event in cyber security insurance is any unauthorized access, breach, or malicious disruption of an organization’s computer network or IT systems that results in financial loss or liability. It serves as the core trigger for policy coverage. Examples include:

· Ransomware and Malware: Malicious software that infects systems, locks data, or halts network operations.

· Data Breaches: Unauthorized actors stealing or exposing sensitive customer, employee, or corporate data.

· Denial of Service (DoS/DDoS): Attacks that flood a network with traffic, making resources unavailable to legitimate users.

· Business Email Compromise (BEC): Unauthorized access to corporate communication channels leading to fraud or data exfiltration.

Insurance coverage. The cyber liability insurance would:

(i) cover immediate operational costs like forensic investigations, mandatory consumer notifications, call centers, and credit-monitoring services for affected individuals.

(ii) protect against lawsuits, customer class-action claims, and legal defense costs if victims sue for the unauthorized exposure of their private data.

(iii) pay for legal representation and potential fines arising from government investigations into privacy law violations (such as HIPAA or state-level privacy statutes).

The following language relating to cyber security can be added to the Management Agreement to set forth the Agent’s obligations in the storage of Personal Information, and consequences of any data breach:

1. “Personal Information” means and includes any information provided to Agent by Owner or Owner’s representatives that either (i) identifies or can be used to identify an individual (including, without limitation, names, signatures, addresses, telephone numbers, e-mail addresses and other unique identifiers), or (ii) can be used to authenticate an individual (including, without limitation, social security numbers, employee identification numbers, government issued identification numbers, passwords or PINs, financial account numbers, credit report information, biometric or health data, answers to security questions and other personal identifiers).

2. The Agent shall develop, implement, and maintain reasonable administrative, technical, and physical safeguards in the use, storage or processing of Personal Information, to ensure that all such safeguards comply with applicable data protection and privacy laws, statutes and regulations and to protect such Personal Information from Data Breach. “Data Breach” means any act or omission that compromises either the security, confidentiality or integrity of Personal Information.

3. If the Agent believes any Personal Information was, or is reasonably believed to have been, accessed or acquired without valid authorization, the Agent shall notify the Owner of the Data Breach as soon as practicable, but no later than three (3) days after Agent becomes aware of such Data Breach. The Agent shall bear all costs and expenses of the investigation and reporting of the Data Beach and shall cooperate with the Owner and Owner’s representatives, including any insurance carriers to which the Owner reports the incident, fully, including without limitation, by providing access to the Owner and/or its representative or carriers, to relevant records, logs, files, data reporting or other materials requested.

4. The Agent shall defend, indemnify, and hold harmless the Owner and its shareholders, directors, officers, members and employees from and against any and all claims, demands, liabilities, damages, losses, fines, penalties, costs, and expenses (including, without limitation, reasonable attorneys’ fees and court costs) arising out of or related to any Data Breach, unauthorized access, or cybersecurity incident involving the Owner’s data, to the extent such incident is caused by the negligence, willful misconduct, or a breach of this Agreement by the Agent.

Without limiting the generality of the foregoing, “losses” shall include:

· Costs of legally required Data Breach notifications.

· Costs of forensic investigations.

· Expenses for identity theft protection and credit monitoring for affected individuals.

· Civil fines, penalties, or assessments issued by regulatory authorities or payment card processors.

Bonnie Reid Berkow is a partner at Adam Leitman Bailey P.C. in the Coop/Condo Litigation Group.

We don't support Internet Explorer

Please use Chrome, Safari, Firefox, or Edge to view this site.