Background
Panasonic Canada suffered a 2022 cyberattack after malware entered its network. The attackers accessed and posted sensitive files online, warned that data had been encrypted, and invited Panasonic to make contact, implying that a ransom would be required for decryption. Panasonic did not negotiate or pay a ransom. It instead incurred about US$2 million responding to the incident, including forensic, legal, network-repair, equipment, and overtime costs.
Panasonic claimed under several first-party, third-party, and breach-response coverages in XL Specialty Insurance Company’s cyber policy. The base policy carried a US$1.5 million retention. A ransomware endorsement, however, provided a US$3 million retention for “ransomware event loss,” broadly defined to include loss arising from, connected with, or involving a cyber-extortion threat. The application judge held that Panasonic could rely on the base-policy coverage grants and apply the lower retention.
The Court’s Holding
The Court of Appeal allowed XL’s appeal. It held that the endorsement applied to Panasonic’s claim and that the applicable retention was US$3 million. The endorsement was a standard-form insurance provision, its interpretation had precedential value, and no party-specific factual matrix materially assisted interpretation; accordingly, the court reviewed the issue for correctness.
Reading the endorsement together with the policy, the court concluded that it governed all claims for ransomware-event loss, whether or not Panasonic chose to frame its claim under the endorsement. The attackers’ communications and conduct fell within the endorsement’s definitions of a cyber-extortion threat and ransomware-event loss. The application judge erred by reading the definitions in isolation and by failing to give effect to the endorsement’s provisions amending the policy and making the endorsement control over inconsistent policy terms.
Key Takeaways
- A ransomware endorsement can govern a loss claimed under other policy coverage grants when its language broadly captures ransomware-event loss.
- An insured’s choice not to pay a ransom or seek cyber-extortion reimbursement does not prevent a ransomware retention from applying.
- Where a standard-form policy provision is precedential and no party-specific factual matrix is material, appellate review of its interpretation is for correctness.
Why It Matters
The decision underscores that cyber-policy endorsements must be read as amendments to the policy as a whole, rather than as optional standalone coverages. Broad “arising out of” and “in connection with” wording may subject incident-response losses to ransomware-specific retentions even where no ransom is paid.
Because Panasonic’s agreed loss was below the US$3 million retention, it was wholly self-insured. The court substituted that declaration, dismissed Panasonic’s application, and awarded XL costs.