<!--
Insurer: AIG (aig)
Product: AIG CyberEdge (cyber-liability)
Vertical: commercial-liability
Wording effective: 2024-05-27
Source PDF: https://www.aig.co.nz/content/dam/aig/apac/new-zealand/new-documents/aig-nz-cyberedge-policy-wording.pdf.coredownload.pdf
PDF sha-256: a7fb8a58be4bdb5ec15f4577ae9a3dc96fbbdaa7b4620227f753e3ab6fd6f53a
Ingested: 2026-05-21T09:09:17.419498+00:00
Canonical URL: https://insurenz.co.nz/api/commercial-liability/product/aig/cyber-liability/wording.md
License: CC BY 4.0 — attribute https://insurenz.co.nz
This file is a markdown transcription of the source PDF via Haiku vision. The
authoritative document is the source PDF linked above. Cite both.
-->

> _Markdown transcription of AIG AIG CyberEdge policy wording, effective 2024-05-27. Source: https://www.aig.co.nz/content/dam/aig/apac/new-zealand/new-documents/aig-nz-cyberedge-policy-wording.pdf.coredownload.pdf_

---

# CyberEdge® Policy Wording

## Policy Introduction

### About the Policy

Your policy is made up of this document, the Schedule and any Endorsements and they should all be read as one document.

Your policy is a legal contract between You and the Insurer.

If You think that any details contained in these documents are not correct or if You need to change anything, You should ask Your insurance intermediary to tell the Insurer.

There are specific conditions, specific exclusions and specific definitions that only apply to a specific policy Section. In addition, there are general conditions, general exclusions, general Claims conditions and general definitions that are part of this policy and apply to each policy Section.

You only have cover under those Sections of the policy for which the details for that Section are completed in the Schedule.

### Copyright

The content of this policy, including but not limited to the text and images herein, and their arrangement, is the copyright property of the Insurer. All rights reserved. The Insurer hereby authorises you to copy and display the content herein, but only in connection with the Insurer's business. Any copy You make must include this copyright notice. Limited quotations from the content are permitted if properly attributed to the Insurer; however, except as set forth above, You may not copy or display for redistribution to Third Parties any portion of the content of this policy without the prior written permission of the Insurer. No modifications of the content may be made. Nothing contained herein shall be construed as conferring by implication or otherwise any license or right under any patent, trademark, copyright (except as expressly provided above), or other proprietary rights of the Insurer or of any Third Party.

### Important Notice

#### CLAIMS-MADE AND NOTIFIED INSURANCE

Section A Directors and Officers' Liability, Corporate Liability, Employment Practices Liability, Statutory Liability, Employers' Liability, Crime Protection, Tax Audit and Review, and Section B of this policy contains coverage on a Claims-made and notified basis. This means that this policy only covers Claims first made against You during the Policy Period and first notified to the Insurer in writing during the Policy Period. This policy does not provide cover for any Claims made against You during the Policy Period if at any time prior to the commencement of the Policy Period You became aware of facts which might give rise to those Claims being made against You.

Section A Directors and Officers' Liability, Corporate Liability, Employment Practices Liability, Statutory Liability, Employers' Liability, Crime Protection, Tax Audit and Review and Section B of this policy do not cover Claims arising out of, based upon or attributable to any:

a) facts alleged or the same or related acts, errors or omissions alleged or contained in any Claim which has or should have been notified or in any circumstances of which notice has or should have been given under any policy of which this policy is a renewal or replacement or which it may succeed in time; or

b) any pending or prior or civil, criminal, administrative or regulatory proceeding, investigation, arbitration or adjudication as of the Continuity Date, or alleging or deriving from the same or essentially the same facts as alleged in such actions.

#### YOUR DUTY OF DISCLOSURE

Before you enter into a contract of insurance with the Insurer, You have a duty to disclose to the Insurer every matter that You know, or could reasonably be expected to know, is relevant to the Insurer's decision whether to accept the risk of the insurance and, if so, on what terms.

You have the same duty to disclose those matters to the Insurer before You renew, extend, vary or reinstate a contract of general insurance.

Your duty however does not require You to disclose a matter:

- that diminishes the risk to be undertaken by the Insurer;
- that is of common knowledge;
- that the Insurer knows or, in the ordinary course of business, ought to know; or
- as to which compliance with Your duty is waived by the Insurer.

#### NON-DISCLOSURE

If You fail to comply with Your duty of disclosure the Insurer may avoid the contract from its beginning.

For further details of the circumstances in which the Insurer has the ability to avoid cover, please see clause 2 of the General Provisions.

### Privacy

The Insurer complies with the Information Privacy Principles. The Information Privacy Principles apply to any Personal Information collected by the Insurer.

#### PURPOSE OF COLLECTION

The Insurer collects Personal Information about You for the purposes of assessing Your application for insurance and administering Your policy. Failure to provide relevant Personal Information may result in the Insurer not being able to administer Your policy, process any Claim under Your policy or You may breach Your duty of disclosure.

#### DISCLOSURE

In the course of administering your policy the Insurer may disclose Your information to:

- an entity to which the Insurer is related either in New Zealand or overseas;
- contractors or Third Party providers providing services related to the administration of Your policy;
- banks and Financial Institutions for the purpose of processing Your application for insurance and obtaining policy payments;
- in the event of a Claim, assessors, lawyers, Third Party administrators, emergency providers and medical providers;
- Third Party service providers to enable the Insurer to advise You of their insurance products or services; and
- reinsurers for the purpose of obtaining reinsurance, if required.

The Insurer will only disclose Your Personal Information to these parties for the primary purpose for which it was collected or to enable the Insurer to advise You of its insurance products or services. In some circumstances the Insurer is entitled to disclose Your Personal Information to Third Parties without Your authorisation such as law enforcement agencies or government authorities.

#### ACCESS TO YOUR INFORMATION

You may gain access to Your information by submitting a written request to the Insurer. In some circumstances the Insurer may not permit access to Your Personal Information. Circumstances where access may be denied include where it would compromise the privacy of other individuals or where it would be unlawful.

The Insurer has also established an internal dispute resolution process for handling customer complaints and an access and correction procedure. Both procedures are generally free of charge however the Insurer reserves the right to charge for access requests in limited circumstances.

If You feel You have a complaint about the Insurer's information privacy principles, require assistance in lodging a privacy complaint or You wish to gain access to Your information, You may write to:

The Privacy Manager
AIG Insurance New Zealand Limited
PO Box 1745 Shortland Street
Auckland 1140
(64) 9 355 3100
privacy.officerNZ@aig.com

Your complaint will be reviewed and You will be provided with a written response. If it cannot be resolved, Your complaint will be referred to the Internal Disputes Resolution Committee who will respond within 15 business days. In either case the matter will be reviewed by a person or persons with appropriate authority to deal with the complaint. Should Your complaint not be resolved by the Insurer's internal dispute resolution process, You may take Your complaint to the Privacy Commissioner for review of the determination.

## Dispute Resolution Process

The Insurer is committed to handling any complaints about its products or services efficiently and fairly.

If You have a complaint about the Insurer's products or services, contact Your insurance intermediary and they may raise it with the Insurer.

If Your complaint is not satisfactorily resolved You may request that Your matter be reviewed by management by writing to:

The Complaints Manager
AIG Insurance New Zealand Limited
PO Box 1745 Shortland Street
Auckland 1140
customerfeedbacknz@aig.com

If You are still unhappy, You may request that the matter be reviewed by the Insurer's Internal Dispute Resolution Committee. The Insurer will respond to You with the Committee's findings within 15 business days.

If You are not satisfied with the finding of the Committee, You may be able to take Your matter to the insurance industry's independent dispute resolution body. This external dispute resolution body can make decisions with which the Insurer is obliged to comply.

---

# Section A: CyberEdge Coverage

## Event Management Coverage

### 1. Insurance Covers

#### 1.1 EVENT MANAGEMENT

The Insurer will pay to or on behalf of each Company:

(i) Legal Expenses;
(ii) IT Expenses;
(iii) Data Recovery Expenses;
(iv) Reputation Protection Expenses;
(v) Notification Expenses;
(vi) Credit Monitoring and ID Monitoring Expenses;
(vii) (if Bricking Recovery Expenses Cover is Included) Bricking Recovery Expenses; and
(viii) (if First Response Cover is Included) First Response Expenses,

incurred solely as a result of an Insured Event which has occurred, or the Company's Responsible Officer reasonably believes has occurred, before or during the Policy Period, and of which the Company's Responsible Officer first becomes aware during the Policy Period.

First Response Expenses will only be paid by the Insurer to the extent that they are incurred during the period commencing when the Company's Responsible Officer first notifies the First Response Advisor of the Insured Event by contacting the Emergency Number specified in the schedule and continuing for the number of hours stated for the First Response Cover in the schedule.

No Retention shall apply to First Response Expenses.

### 2. Definitions

The following definitions are specific to this Event Management Coverage Section. All other definitions set out within Section 9 (Definitions) of the General Terms and Conditions shall apply as stated.

#### BREACH OF CONFIDENTIAL INFORMATION

Unauthorised access to or unauthorised disclosure of Confidential Information.

#### BRICKING RECOVERY EXPENSES

The reasonable and necessary fees, costs and expenses incurred by a Company, with the Insurer's prior written consent, on actions taken to replace any part of a Company Computer System on which lost, damaged, destroyed, encrypted or corrupted Data was stored that is no longer functional, but only:

(i) where such actions are reasonable and are necessary to restore, recreate, repair or recollect such Data in accordance with subparagraph (iii) of the "Data Recovery Expenses" Definition; and

(ii) to the extent that cover for such fees, costs and expenses are not available under the Network Interruption Coverage Section.

#### COMPANY COMPUTER SYSTEM

(i) Any computer hardware, software or any components thereof that are linked together through a network of two or more devices accessible through the internet or an intranet or that are connected through Data storage or other peripheral devices which are owned, operated, controlled or leased by a Company;

(ii) any of the foregoing computer hardware, software or components thereof which is part of an industrial control system, including a supervisory control and Data acquisition (SCADA) system; or

(iii) any Employee "Bring Your Own Device" but only to the extent such device is used to access any of the foregoing computer hardware, software or components thereof or Data contained therein.

For the purposes of Bricking Recovery Expenses only, Company Computer System shall not include subparagraph (iii) above.

#### CONFIDENTIAL INFORMATION

Corporate Information and Personal Information in a Company's or Information Holder's care, custody or control or for which a Company is legally responsible.

#### CORPORATE INFORMATION

A Third Party's items of information that are not available to the public (including trade secrets, Data, designs, forecasts, formulas, practices, processes, records, reports and documents) which are subject to contractual or legal protection.

#### CREDIT MONITORING AND ID MONITORING EXPENSES

The reasonable and necessary fees, costs and expenses incurred by a Company, with the Insurer's prior written consent, for Credit Monitoring and ID Monitoring Services provided to those Data Subjects whose Personal Information is reasonably believed to have been disclosed or transmitted. Such fees, costs and expenses will only be paid by the Insurer for Data Subjects that request and/or activate the Credit Monitoring and ID Monitoring Services within ninety (90) days after receiving notification from the Company that their Personal Information is reasonably believed to have been disclosed or transmitted. In such a case, Credit Monitoring and ID Monitoring Services will only be provided to each such Data Subject for a period of two (2) years from the date of activation.

#### CREDIT MONITORING AND ID MONITORING SERVICES

Credit or identity theft monitoring services to identify possible misuse of any Personal Information as a result of an actual or suspected Breach of Confidential Information.

#### CYBER TERRORISM

The premeditated use of disruptive activities against a Company Computer System or network, or the explicit threat to use such activities, by an individual or group of individuals, whether acting alone or on behalf of or in connection with any entity or government, in each case with the intention to cause harm, further social, ideological, religious, political or similar objectives, or to intimidate any person(s) in furtherance of such objectives.

Cyber Terrorism does not include any such activities which are part of or in support of any use of military force or war.

#### DATA PROTECTION LEGISLATION

The Privacy Act 2020, and any subsequent legislation that alters, repeals or replaces such legislation and all other equivalent laws and regulations relating to the regulation and enforcement of Data protection or Data privacy in any country.

#### DATA RECOVERY EXPENSES

The reasonable and necessary fees, costs and expenses incurred by a Company, with the Insurer's prior written consent, on actions taken to:

(i) identify lost, damaged, destroyed, encrypted or corrupted Data;

(ii) determine whether any lost, damaged, destroyed, encrypted or corrupted Data can be restored, repaired, recollected or recreated; and

(iii) restore, recreate, repair or recollect lost, damaged, destroyed, encrypted or corrupted Data to substantially the form in which it existed immediately prior to the Insured Event, including where necessary the cost to restore Data from backups or recreate Data from physical records.

#### DATA SUBJECT

Any natural person whose Personal Information has been either collected, stored or processed by or on behalf of a Company.

#### FIRST RESPONSE ADVISOR

The law firm specified in the schedule, or other law firms instructed by such specified law firm, or any replacement firm nominated by the Insurer in the event of a conflict of interest, with respect to whom a Company shall enter into a Relevant Engagement.

#### FIRST RESPONSE EXPENSES

The reasonable and necessary fees, costs and expenses (as determined by the Insurer at its sole discretion) of:

(i) the First Response Advisor providing First Response Legal Services;

(ii) the First Response IT Specialist providing IT Services; and

(iii) the Public Relations Advisor, if its appointment is considered necessary by the First Response Advisor or the Insurer, providing Reputation Protection Services.

#### FIRST RESPONSE IT SPECIALIST

The information technology services firm appointed by the Insurer or First Response Advisor.

#### FIRST RESPONSE LEGAL SERVICES

(i) legal advice and support provided pursuant to a Relevant Engagement;

(ii) coordinating the First Response IT Specialist, and, if considered necessary by the First Response Advisor or Insurer, the Public Relations Advisor; and

(iii) preparation of notices and notification to any relevant Regulator.

#### INFORMATION HOLDER

A Third Party that holds Personal Information or Corporate Information on behalf of a Company.

#### INSURED

A Company.

#### INSURED EVENT

(i) A Breach of Confidential Information;

(ii) a Security Failure; or

(iii) in respect of Data Recovery Expenses only, an Operational Failure.

#### IT EXPENSES

The reasonable and necessary fees, costs and expenses (as determined by the Insurer at its sole discretion) of an IT Specialist providing IT Services.

#### IT SERVICES

The services of:

(i) substantiating whether an Insured Event has occurred, how it occurred and whether it is still occurring;

(ii) identifying any compromised Data resulting from an Insured Event;

(iii) establishing the extent to which Confidential Information may have been compromised resulting from an Insured Event; or

(iv) containing and resolving an Insured Event and making recommendations to prevent or mitigate a future occurrence of the same or similar event.

#### IT SPECIALIST

An information technology services firm appointed by the Insurer, the Response Advisor, or a Company where that firm has been approved by the Insurer in advance of such appointment.

#### LEGAL EXPENSES

The reasonable and necessary fees, costs and expenses (as determined by the Insurer at its sole discretion) of a Response Advisor providing Legal Services.

#### LEGAL SERVICES

The services of:

(i) co–ordinating the IT Specialist or Public Relations Advisor;

(ii) advising, notifying and corresponding on any notification requirements with any relevant Regulator; or

(iii) monitoring complaints raised by Data Subjects and advising a Company on responses to an Insured Event for the purposes of minimising harm to the Company, including actions taken to maintain and restore public confidence in the Company, in dealing with any actual or suspected Breach of Confidential Information or Security Failure.

#### LOSS

Legal Expenses, IT Expenses, Data Recovery Expenses, Reputation Protection Expenses, Notification Expenses, Credit Monitoring and ID Monitoring Expenses, Bricking Recovery Expenses and First Response Expenses.

#### NOTIFICATION EXPENSES

The reasonable and necessary fees, costs and expenses incurred by a Company, with the Insurer's prior written consent, of:

(i) investigating and collating information;

(ii) preparing notices and notifying:

(a) those Data Subjects whose Personal Information is reasonably believed to have been subject to unauthorised access or disclosure; and

(b) any Third Party whose Corporate Information is reasonably believed to have been subject to unauthorised access or disclosure; and

(c) any relevant Regulator; and

(iii) setting up and operating call centres,

with regard to any actual or suspected Breach of Confidential Information.

#### OPERATIONAL FAILURE

The loss or damage to Data caused by:

(i) a negligent or unintentional act or failure to act by:

(a) an Insured;

(b) an Employee of an Insured; or

(c) a third-party service provider to an Insured;

(ii) the Loss or theft of electronic equipment; or

(iii) a magnetic event other than:

(a) the use of electromagnetic or directed-energy weapons; or

(b) the natural deterioration of the storage media or Data.

#### PERSONAL INFORMATION

Any information relating to an identified or identifiable natural person.

Personal Information includes a natural person's name, national registration identification number, telephone number, credit card or debit card number, account and other banking information, medical information, or any other information about a natural person protected under any Data Protection Legislation.

#### PUBLIC RELATIONS ADVISOR

A consultant appointed by the Insurer or the Response Advisor, or any other consultant appointed by a Company that has been approved by the Insurer in advance of such appointment, to provide Reputation Protection Services.

#### REGULATOR

A Regulator established pursuant to Data Protection Legislation in any jurisdiction and which is authorised to enforce statutory obligations in relation to the collection, disclosure, storage, processing or control of Confidential Information.

Regulator includes any other government agency or authorised Data protection authority who makes a demand on a Company in relation to Data Protection Legislation.

#### RELEVANT ENGAGEMENT

A written agreement between the First Response Advisor and a Company governing the provision of the First Response Legal Services to the Company.

#### REPUTATION PROTECTION EXPENSES

The reasonable and necessary fees, costs and expenses (as determined by the Insurer at its sole discretion) of a Public Relations Advisor providing Reputation Protection Services.

#### REPUTATION PROTECTION SERVICES

Advice and support (including advice concerning media strategy and independent public relations services, and the design and management of a communications strategy) in order to mitigate or prevent the potential adverse effect of, or reputational damage from, media reporting of an Insured Event.

#### RESPONSE ADVISOR

Any law firm appointed by the Insurer, or any other law firm appointed by a Company that has been approved by the Insurer in advance of such appointment.

#### SECURITY FAILURE

(i) Any intrusion of, unauthorised access (including an unauthorised person using authorised credentials) to, or unauthorised use of (including by a person with authorised access) a Company Computer System, including that which results in or fails to mitigate any:

(a) denial of service attack or denial of access; or

(b) receipt or transmission of a malicious code, malicious software or virus;

(ii) The Loss of Data arising from the physical theft or Loss of hardware controlled by a Company; or

(iii) the unauthorised reprogramming or corruption of software (including firmware) which renders a Company Computer System or any component thereof non-functional or useless for its intended purpose.

### 3. Exclusions

The following Exclusions are specific to this Event Management Coverage Section. They apply in addition to the Exclusions in Section 10 (Exclusions) of the General Terms and Conditions.

The Insurer shall not be liable for any Loss:

#### 3.1 BETTERMENT

Consisting of the costs of:

(i) updating, upgrading, enhancing or replacing a Company Computer System to a level beyond that which existed prior to the occurrence of an Insured Event, however, where Bricking Recovery Expenses Cover is Included, this Exclusion 3.1 (i) shall not apply to:

(a) the patching or updating of a component of the Company Computer System required to resolve a Security Failure or Breach of Confidential Information; or

(b) the replacement of a component of the Company Computer System required to restore, recreate, repair or recollect damaged, destroyed or corrupted Data which can only be reasonably replaced with an upgraded or enhanced component, but in such circumstances, only for the cost of such upgraded or enhanced component that most closely matches the functionality of the component to be replaced;

(ii) removing software program errors or vulnerabilities.

#### 3.2 BODILY INJURY AND PROPERTY DAMAGE

Arising out of, based upon or attributable to any:

(i) physical injury, mental illness, sickness, disease or death; or

(ii) Loss, damage or destruction of tangible property, however, where Bricking Recovery Expenses Cover is Included, this Exclusion 3.2 (ii) shall not apply to the Loss of use of electronic equipment caused by the reprogramming of the software (including firmware) of such electronic equipment rendering it useless for its intended purpose.

#### 3.3 GOVERNMENT ENTITY OR PUBLIC AUTHORITY

Arising out of, based upon or attributable to any seizure, confiscation or nationalisation of a Company Computer System by order of any government entity or public authority.

#### 3.4 INFRASTRUCTURE

Arising out of, based upon or attributable to any electrical or mechanical failure of infrastructure not under the control of a Company, including any electrical power interruption, surge, brownout or blackout, failure of telephone lines, Data transmission lines, or other telecommunications or networking infrastructure.

This Exclusion 3.4 shall not apply to Loss arising out of, based upon or attributable solely to a Security Failure or Breach of Confidential Information that is caused by such electrical or mechanical failure of infrastructure.

#### 3.5 INTERNAL/STAFF COSTS

Consisting of the costs of payroll, fees, benefits, overheads or internal charges of any kind incurred by a Company.

#### 3.6 PATENT/TRADE SECRET

Arising out of, based upon or attributable to any:

(i) infringement of patents;

(ii) Loss of rights to secure registration of patents; or

(iii) misappropriation of trade secrets by or for the benefit of a Company.

#### 3.7 WAR AND TERRORISM

Arising out of, based upon or attributable to any war (whether war is declared or not), terrorism (except Cyber Terrorism), invasion, use of military force, civil war, popular or military rising, rebellion or revolution, or any action taken to hinder or defend against any of these events.

### 4. Conditions

The following conditions are specific to this Event Management Coverage Section and shall apply in addition to the conditions (including notice provisions) set out within the General Terms and Conditions.

#### 4.1 FIRST RESPONSE NOTIFICATION

The cover provided for First Response Expenses is granted solely with respect to a Breach of Confidential Information or Security Failure first Discovered during the Policy Period and a Company shall, as a condition precedent to the obligations of the Insurer in respect of such First Response Expenses, notify the Insurer by contacting the Emergency Number specified in the schedule as soon as reasonably practicable after the Breach of Confidential Information or Security Failure first occurs.

---

## Network Interruption Coverage

### 1. Insurance Covers

#### 1.1 NETWORK INTERRUPTION LOSS

The Insurer will, with regard to an Insured Event which first occurs during the Policy Period, pay to each Company:

(i) Network Loss which results from the Insured Event and which the Company incurs during the Insured Event (but, if the Insured Event lasts longer than 120 days, only during the first 120 days of the Insured Event); and

(ii) Network Loss which results from the Insured Event and which the Company incurs during the 90 days following resolution of the Insured Event.

#### 1.2 INTERRUPTION AND MITIGATION COSTS

The Insurer will pay, to or on behalf of each Company, Network Interruption Costs incurred in mitigating the impact of an Insured Event which first occurs during the Policy Period.

#### 1.3 LOSS PREPARATION COSTS

If Loss Preparation Costs Cover is Included, the Insurer will pay to or on behalf of each Company, Loss Preparation Costs incurred as a result of an Insured Event which first occurs during the Policy Period.

### 2. Definitions

The following definitions are specific to this Network Interruption Coverage Section. All other definitions set out within Section 9 (Definitions) of the General Terms and Conditions shall apply as stated.

#### COMPANY COMPUTER SYSTEM

(i) Any computer hardware, software or any other components thereof that are linked together through a network of two or more devices accessible through the internet or an intranet or that are connected through Data storage or other peripheral devices which are owned, operated, controlled or leased by a Company; or

(ii) any of the foregoing computer hardware, software or components thereof which is part of an industrial control system, including a supervisory control and Data.

#### CYBER TERRORISM

The premeditated use of disruptive activities against a Company Computer System or network, or the explicit threat to use such activities, by an individual or group of individuals, whether acting alone or on behalf of or in connection with any entity or government, in each case with the intention to cause harm, further social, ideological, religious, political or similar objectives, or to intimidate any person(s) in furtherance of such objectives.

Cyber Terrorism does not include any such activities which are part of or in support of any use of military force or war.

#### INCREASED COSTS OF WORKING

Expenses (including overtime of Employees) incurred over and above normal operating expenses in order to ensure continuation of the normal business operations of a Company and to reduce its Loss of business income.

#### INSURED

A Company.

#### INSURED EVENT

(i) If Security Failure Cover is Included, a Material Interruption to a Company Computer System that is caused by a Security Failure;

(ii) if System Failure Cover is Included, a Material Interruption to a Company Computer System that is caused by a System Failure;

(iii) if Voluntary Shutdown Cover is Included, a Material Interruption to a Company Computer System that is caused by a Voluntary Shutdown;

(iv) if Regulatory Shutdown Cover is Included, a Material Interruption to a Company Computer System that is caused by a Regulatory Shutdown;

(v) if OSP Security Failure Cover is Included, a Material Interruption to an OSP Computer System that is caused by an OSP Security Failure; and

(vi) if OSP System Failure Cover is Included, a Material Interruption to an OSP Computer System that is caused by an OSP System Failure,

and in each case, only where the duration of the Material Interruption exceeds the applicable Waiting Hours Period specified in the schedule.

#### LOSS

(i) for the purposes of Insurance Covers 1.1, Network Loss

(ii) for the purposes of Insurance Covers 1.2, Network Interruption Costs

(iii) for the purposes of Insurance Covers 1.3, Loss Preparation Costs

#### LOSS PREPARATION COSTS

Reasonable and necessary professional fees and expenses incurred by a Company with the Insurer's prior written consent, for the services of a third-party forensic accounting firm to establish, prove, verify or quantify Network Loss or Network Interruption Costs or prepare the proof of Loss referred to in Condition 4.1 of this Network Interruption Coverage Section.

#### MATERIAL INTERRUPTION

(i) The suspension or degradation of a Company Computer System (for the purposes of Insured Event (i) – (iv)) or an OSP Computer System (for the purposes of Insured Event (v) or (vi)) causing the Company to be unable to continue the normal business operations of the Company; or

(ii) the deletion, damage, corruption, alteration or Loss of or to Data on a Company Computer System (for the purposes of Insured Event (i) – (iv)) or an OSP Computer System (for the purposes of Insured Event (v) or (vi)) causing the Company to be unable to access that Data and unable to continue the normal business operations of the Company.

#### NETWORK INTERRUPTION COSTS

The reasonable and necessary costs and expenses that a Company incurs to minimise the Network Loss, or reduce the impact of a Material Interruption; provided however that the amount of Network Loss prevented or reduced must be greater than the costs and expenses incurred.

#### NETWORK LOSS

(i) A Company's actual Loss sustained resulting from the reduction in business income calculated by taking either Network Loss Option 1 or Network Loss Option 2; and

(ii) the Company's Increased Costs of Working (but only up to an amount equal to the reduction in the business income that would have been incurred had the Company been unable to continue its normal business operations).

Network Loss Option 1 (Net Profit and Continuing Fixed Costs Calculation) is calculated as follows:

Take the net profit or Loss which would have been earned or incurred had the Material Interruption not occurred and add the costs (including ordinary payroll) which necessarily continue during the Material Interruption.

Network Loss Option 2 (Gross Profits Calculation) is calculated as follows:

Take the revenue which would have been derived from the operation of the business had the Material Interruption not occurred and subtract the variable costs, and any other costs, which do not necessarily continue during the Material Interruption.

#### OSP COMPUTER SYSTEM

Any computer hardware, software or any components thereof that are linked together through a network of two or more devices accessible through the internet or an intranet or that are connected through Data storage or other peripheral devices which are owned, operated, controlled or leased by an Outsource Service Provider.

#### OSP SECURITY FAILURE

Any intrusion of, unauthorised access (including any unauthorised person using authorised credentials) to, or unauthorised use of (including by a person with authorised access) an OSP Computer System, including that which results in or fails to mitigate any:

(i) denial of service attack or denial of access; or

(ii) receipt or transmission of a malicious code, malicious software or virus.

#### OSP SYSTEM FAILURE

Any unintentional and unplanned outage of an OSP Computer System such that the Outsource Service Provider is unable to provide to a Company the services described in a contract between a Company and an Outsource Service Provider pursuant to which an Outsource Service Provider provides services to a Company for a fee.

#### OUTSOURCE SERVICE PROVIDER

A Third Party that a Company has appointed to provide specified information technology services (such as the processing, hosting and storage of Data) to the Company based on an express contractual agreement, but only to the extent of the provision of such services.

Outsource Service Provider does not include:

(i) a public utility (including a provider of electricity, gas, water or telecommunication services);

(ii) an internet service provider (including any provider of internet connectivity); or

(iii) a Securities exchange or market.

#### REGULATORY SHUTDOWN

An intentional shutdown or impairment of a Company Computer System by an Insured, necessary to comply with an enforceable legal or regulatory order pursuant to Data Protection Legislation resulting directly and solely from a Security Failure.

#### SECURITY FAILURE

(i) Any intrusion of, unauthorised access (including an unauthorised person using authorised credentials) to, or unauthorised use of (including by a person with authorised access) a Company Computer System, including that which results in or fails to mitigate any:

(a) denial of service attack or denial of access; or

(b) receipt or transmission of a malicious code, malicious software or virus; or

(ii) the unauthorised reprogramming or corruption of software (including firmware) which renders a Company Computer System or any component thereof non-functional or useless for its intended purpose.

#### SYSTEM FAILURE

Any unintentional and unplanned outage of a Company Computer System.

#### VOLUNTARY SHUTDOWN

A voluntary and intentional shutdown or impairment of a Company Computer System by or at the direction of:

(i) the Chief Information officer or Chief Information Security Officer of a Company (or the equivalent position regardless of title) who has at least 5 years' experience in an Information Security or Technology role; or

(ii) an information technology services firm appointed by a Company that has been approved by the Insurer in advance of such appointment,

after the Discovery of a Security Failure, with the reasonable belief that such shutdown or impairment would limit the Loss that would otherwise be incurred as a result of that Security Failure.

### 3. Exclusions

The following Exclusions are specific to this Network Interruption Coverage Section. They apply in addition to the Exclusions in Section 10 (Exclusions) of the General Terms and Conditions.

The Insurer shall not be liable for Loss:

#### 3.1 BETTERMENT

Consisting of the costs of:

(i) updating, upgrading, enhancing or replacing any component of a Company Computer System or an OSP Computer System to a level beyond that which existed prior to the occurrence of a Material Interruption; however, this exclusion shall not apply to the extent that the replacement of a component of a Company Computer System is:

(a) required to end the Material Interruption; and

(b) no longer available and can only be reasonably replaced with an upgraded or enhanced version; or

(ii) removing software program errors or vulnerabilities.

#### 3.2 BODILY INJURY AND PROPERTY DAMAGE

Arising out of, based upon or attributable to any:

(i) physical injury, mental illness, sickness, disease or death; or

(ii) Loss, damage or destruction of tangible property; however, where Bricking Recovery Expenses Cover is Included, this Exclusion 3.2 (ii) shall not apply to the Loss of use of electronic equipment caused by the reprogramming of the software (including firmware) of such electronic equipment rendering it useless for its intended purpose.

#### 3.3 BUSINESS CONDITIONS

Consisting of loss of earnings, or costs or expenses, attributable to unfavourable business conditions.

#### 3.4 GOVERNMENT ENTITY OR PUBLIC AUTHORITY

Arising out of, based upon or attributable to any seizure, confiscation or nationalisation of a Company Computer System by order of any government entity or public authority.

#### 3.5 INFRASTRUCTURE

Arising out of, based upon or attributable to any electrical or mechanical failure of infrastructure not under the control of a Company (or, where OSP Security Failure Cover or OSP System Failure Cover is Included, an Outsource Service Provider), including any electrical power interruption, surge, brownout or blackout, failure of telephone lines, Data transmission lines, or other telecommunications or networking infrastructure.

#### 3.6 LIABILITY

Arising out of, based upon or attributable to any:

(i) written demand, civil, administrative or arbitral proceedings, made by any Third Parties seeking any legal remedy; or

(ii) penalties paid to Third Parties.

#### 3.7 PATENT

Arising out of, based upon or attributable to any infringement of patents.

#### 3.8 TRADING LOSSES

Consisting of trading Losses, liabilities or changes in trading account value.

#### 3.9 WAR AND TERRORISM

Arising out of, based upon or attributable to any war (whether war is declared or not), terrorism (except Cyber Terrorism), invasion, use of military force, civil war, popular or military rising, rebellion or revolution, or any action taken to hinder or defend against any of these events.

### 4. Conditions

The following conditions are specific to this Network Interruption Coverage Section and shall apply in addition to the conditions set out within the General Terms and Conditions.

#### 4.1 PROOF OF LOSS

In addition to the requirements to give notice to the Insurer under Section 7.1 (Notice and Reporting) of the General Terms and Conditions, and before coverage under this Network Interruption Coverage Section shall apply, a Company must also:

(i) complete and sign a written, detailed and affirmed proof of Loss after the resolution of the Material Interruption, which will include:

(a) a full description of the Network Interruption Costs or Network Loss and the circumstances of such Network Interruption Costs or Network Loss;

(b) a detailed calculation of any Network Loss;

(c) all underlying documents and materials that reasonably relate to or form a part of the basis of the proof of the Network Interruption Costs or Network Loss; and

(ii) upon the Insurer's request promptly respond to requests for information.

All adjusted claims are due and payable 45 days after:

(a) the presentation of the satisfactory written proof of Network Loss and Network Interruption Costs as provided for in (i) and (ii) above; and

(b) the subsequent written acceptance thereof by the Insurer.

Network Loss shall be reduced by any amounts recovered by a Company (including the value of any service credits provided to a Company) from any party (including any Outsource Service Provider).

The costs and expenses of establishing or proving Network Loss and/or Network Interruption Costs under this Network Interruption Coverage Section, including those associated with preparing the proof of Loss, shall be the obligation of the Company and are not covered under this policy except as covered under 1.3 (Loss Preparation Costs) of this Network Interruption Coverage Section.

#### 4.2 APPRAISAL

If a Company and the Insurer disagree on the extent of Network Loss or Network Interruption Costs, either may make a written demand for an appraisal of such Network Loss or Network Interruption Costs. If such demand is made, each party will select a competent and impartial appraiser. The appraisers will then jointly select an expert who has not less than 10 years' standing and who is a partner in a major international accounting firm, experienced in assessing Loss of this nature. Each appraiser will separately state the extent of Network Loss or Network Interruption Costs. If they fail to agree, they will submit their differences to the expert. Any decision by the expert will be final and binding.

The Company and the Insurer will:

(i) pay their own costs, including the costs of their respective chosen appraiser, and

(ii) bear the expenses of the expert equally.

---

## Security and Privacy Liability Coverage

### 1. Insurance Covers

#### 1.1 DATA PROTECTION INVESTIGATION AND DATA PROTECTION FINES

The Insurer will pay, to or on behalf of each Company, Loss resulting from a Regulatory Investigation first occurring during the Policy Period.

#### 1.2 CYBER LIABILITY

The Insurer will pay, to or on behalf of each Insured, Loss resulting from a Claim first made and notified during the Policy Period resulting from any:

(i) actual or alleged Breach of Confidential Information by an Insured or an Information Holder;

(ii) actual or alleged Security Failure; or

(iii) actual or alleged failure by a Company to notify a Data Subject or any Regulator of an unauthorised access to or unauthorised disclosure of Personal Information for which the Company is responsible in accordance with the requirements of any Data Protection Legislation,

which occurred or occurs prior to or during the Policy Period.

### 2. Definitions

The following definitions are specific to this Security and Privacy Liability Coverage Section. All other definitions set out within Section 9 (Definitions) of the General Terms and Conditions shall apply as stated.

#### BREACH OF CONFIDENTIAL INFORMATION

The unauthorised access to or unauthorised disclosure of Confidential Information.

#### CLAIM

(i) A written demand against an Insured;

(ii) civil, administrative or arbitral proceedings brought against an Insured; or

(iii) a PCI-DSS Assessment, provided always that the specific Insured which is the subject of the PCI-DSS Assessment was validated as compliant with the generally accepted and published Payment Card Industry Data Security Standards prior to and at the time of any Breach of Confidential Information which gives rise to such PCI-DSS Assessment occurring;

seeking any legal remedy.

#### COMPANY COMPUTER SYSTEM

(i) Any computer hardware, software or any components thereof that are linked together through a network of two or more devices accessible through the internet or an intranet or that are connected through Data storage or other peripheral devices which are owned, operated, controlled or leased by a Company;

(ii) any of the foregoing computer hardware, software or components thereof which is part of an industrial control system, including a supervisory control and Data acquisition (SCADA) system;

(iii) any Employee "Bring Your Own Device" but only to the extent such device is used to access any of the foregoing computer hardware, software or components thereof or Data contained therein; or

(iv) any cloud service or other hosted computer resources, used by a Company and operated by a Third-Party service provider under a written contract between such Third-Party service provider and a Company.

#### CONFIDENTIAL INFORMATION

Corporate Information and Personal Information in a Company's or Information Holder's care, custody or control or for which a Company is legally responsible.

#### CORPORATE INFORMATION

A Third Party's items of information that are not available to the public (including trade secrets, Data, designs, forecasts, formulas, practices, processes, records, reports and documents) which are subject to contractual or legal protection.

#### CYBER TERRORISM

The premeditated use of disruptive activities against a Company Computer System or network, or the explicit threat to use such activities, by an individual or group of individuals, whether acting alone or on behalf of or in connection with any entity or government, in each case with the intention to cause harm, further social, ideological, religious, political or similar objectives, or to intimidate any person(s) in furtherance of such objectives.

Cyber Terrorism does not include any such activities which are part of or in support of any use of military force or war.

#### DAMAGES

Damages that an Insured is legally liable to pay resulting from a Claim as ascertained by:

(i) judgments or arbitral awards rendered against that Insured; or

(ii) a settlement agreement negotiated by that Insured and for which prior written consent has been obtained from the Insurer.

Damages includes punitive or exemplary or multiple damages where lawfully insurable and any monetary amounts that an Insured is required by law or has agreed by settlement to deposit into a consumer redress fund.

#### DATA PROTECTION FINES

Any lawfully insurable fines or penalties which are adjudicated by a Regulator to be payable by a Company for a breach of Data Protection Legislation.

Data Protection Fines does not include any other type of civil or criminal fines and penalties.

#### DATA PROTECTION LEGISLATION

The Privacy Act 2020, and any subsequent legislation that alters, repeals or replaces such legislation and all other equivalent laws and regulations relating to the regulation and enforcement of Data protection or Data privacy in any country.

#### DATA SUBJECT

Any natural person whose Personal Information has been either collected, stored or processed by or on behalf of a Company.

#### DEFENCE COSTS

Reasonable and necessary legal fees, costs and expenses which an Insured incurs with the prior written consent of the Insurer in relation to the investigation, response, defence, appeal or settlement of a Claim or Regulatory Investigation, including court attendance costs incurred by or on behalf of that Insured.

Defence Costs does not include the remuneration of any Insured, cost of their time or any other costs or overheads of any Insured.

#### INFORMATION HOLDER

A Third Party that holds Personal Information or Corporate Information on behalf of a Company.

#### INSURED

(i) A Company;

(ii) a natural person who was, is or during the Policy Period becomes a principal, partner, director, officer or Employee of a Company; or

(iii) a natural person who is an independent contractor, temporary contract labourer, self–employed person, or labour–only subcontractor, under the direction and direct supervision of a Company but only in relation to the services provided to that Company.

Insured includes the estate, heirs or legal representatives of a deceased, legally incompetent or bankrupt Insured referred to in (ii) above to the extent that a Claim is brought against them solely by reason of them having an interest in property that is sought to be recovered in a Claim against such Insured referred to in (ii) above.

#### INSURED EVENT

A Claim or a Regulatory Investigation.

#### LOSS

(i) For the purposes of Insurance Cover 1.1, Defence Costs and Data Protection Fines;

(ii) for the purposes of Insurance Cover 1.2, Damages, Defence Costs and any amounts payable in connection with a PCI-DSS Assessment.

Loss does not include:

(a) non–compensatory or multiple Damages (except to the extent covered as Damages or as part of a PCI-DSS Assessment) or liquidated Damages;

(b) fines or penalties (except Data Protection Fines to the extent covered in 1.1. (Data Protection Investigation and Data Protection Fines));

(c) the costs and expenses of complying with any order for, grant of or agreement to provide injunctive or other non–monetary relief; or

(d) an Insured's remuneration, cost of management or staff time or overheads.

#### PCI–DSS ASSESSMENT

Any written demand received by a Company from a payment card association (e.g., MasterCard, Visa, American Express) or bank or servicer processing payment card transactions (e.g., an "acquiring bank" or "payment processor") for a monetary amount (including fraud recovery, operational reimbursement, reimbursement of card reissuance costs and contractual fines and penalties) where:

(i) a Company has contractually agreed to indemnify such Payment Card Association, bank or servicer processing payment card transactions for any monetary assessment made in connection with a Company's obligations under the Payment Card Industry Data Security Standards, including such contractual obligations contained in a merchant services agreement or similar agreement; and

(ii) such monetary assessment arises out of a Breach of Confidential Information.

#### PERSONAL INFORMATION

Any information relating to an identified or identifiable natural person.

Personal Information includes a natural person's name, national registration identification number, telephone number, credit card or debit card number, account and other banking information, medical information, or any other information about a natural person protected under any Data Protection Legislation.

#### REGULATOR

A Regulator established pursuant to Data Protection Legislation in any jurisdiction and which is authorised to enforce statutory obligations in relation to the collecting, disclosing, storing, processing or control of Confidential Information.

Regulator includes any other government agency or authorised Data protection authority who makes a demand on the Insured in relation to Data Protection Legislation.

#### REGULATORY INVESTIGATION

Any formal or official action, investigation, inquiry or audit by a Regulator against a Company once it is identified in writing by a Regulator, which arises out of the use or suspected misuse of Personal Information or any aspects of the control, collection, storage or processing of Personal Information or delegation of Data processing to an Information Holder, which is regulated by Data Protection Legislation.

Regulatory Investigation does not include any industry-wide, non-firm specific action, investigation, inquiry or audit.

#### SECURITY FAILURE

(i) Any intrusion of, unauthorised access (including an unauthorised person using authorised credentials) to, or unauthorised use of (including by a person with authorised access) a Company Computer System, including that which results in or fails to mitigate any:

(a) denial of service attack or denial of access; or

(b) receipt or transmission of a malicious code, malicious software or virus;

(ii) the Loss of Data arising from the physical theft or Loss of hardware controlled by a Company; or

(iii) the unauthorised reprogramming or corruption of software (including firmware) which renders a Company Computer System or any component thereof non-functional or useless for its intended purpose.

### 3. Exclusions

The following Exclusions are specific to this Security and Privacy Liability Coverage Section. They apply in addition to the Exclusions in Section 10 (Exclusions) of the General Terms and Conditions.

The Insurer shall not be liable for Loss arising out of, based upon or attributable to:

#### 3.1 ANTI–TRUST

Any actual or alleged antitrust violation, restraint of trade, unfair competition or unfair or deceptive business practices, including violation of any consumer protection law.

This Exclusion shall not apply to a Regulatory Investigation alleging such antitrust violation, restraint of trade, unfair competition or unfair or deceptive business practices, including violation of any consumer protection law, directly in connection with a Security Failure or Breach of Confidential Information.

#### 3.2 ASSUMED LIABILITY, GUARANTEE, WARRANTY

Any guarantee, warranty, contractual term or liability assumed or accepted by an Insured under any contract or agreement except to the extent such liability would have attached to the Insured in the absence of such contract or agreement.

This Exclusion shall not apply to:

(i) a contractual obligation to prevent a Security Failure or Breach of Confidential Information;

(ii) an obligation under a written confidentiality or disclosure agreement with a Third Party to prevent a Breach of Confidential Information; or

(iii) the obligation to comply with Payment Card Industry Data Security Standards.

#### 3.3 BODILY INJURY AND PROPERTY DAMAGE

Any:

(i) physical injury, mental illness, sickness, disease or death: however, this Exclusion 3.3 (i) shall not apply in respect of emotional distress or mental anguish arising solely out of a Breach of Confidential Information; or

(ii) Loss, damage or destruction of tangible property.

#### 3.4 EMPLOYMENT PRACTICES LIABILITY

Any of a Company's employment practices (including wrongful dismissal, discharge or termination, discrimination, harassment, retaliation or other employment–related Claim).

This Exclusion shall not apply to any Claim by an individual to the extent such individual is alleging:

(i) a Breach of Confidential Information in connection with such individual's employment or application for employment with a Company; or

(ii) a failure to disclose a Security Failure or Breach of Confidential Information.

#### 3.5 GOVERNMENT ENTITY OR PUBLIC AUTHORITY

Any seizure, confiscation or nationalisation of a Company Computer System by order of any government entity or public authority.

#### 3.6 INFRASTRUCTURE

Any electrical or mechanical failure of infrastructure not under the control of a Company, including any electrical power interruption, surge, brownout or blackout, failure of telephone lines, Data transmission lines, or other telecommunications or networking infrastructure.

This Exclusion shall not apply to Loss arising out of, based upon or attributable solely to a Security Failure or Breach of Confidential Information that is caused by such electrical or mechanical failure of infrastructure.

#### 3.7 INSURED V INSURED

Any Claim brought by or on behalf of an Insured against another Insured.

This Exclusion shall not apply to an actual or alleged unauthorised access to or unauthorised disclosure of Personal Information of any Employee, director, principal, partner or officer.

#### 3.8 PATENT/TRADE SECRET

Any:

(i) infringement of patents;

(ii) loss of rights to secure registration of patents; or

(iii) misappropriation of trade secrets by or for the benefit of a Company.

#### 3.9 Securities Claims

Any:

(i) actual or alleged violation by an Insured of any law, regulation or rule relating to the ownership, purchase, sale or offer of, or solicitation of an offer to purchase or sell, Securities; or

(ii) any actual or alleged violation by an Insured of any provision of the Securities Act of 1933, the Securities Exchange Act of 1934 (each a United States of America statute) or any similar law of any jurisdiction.

This Exclusion shall not apply to any Damages or Defence Costs incurred in relation to a Claim solely alleging a failure to notify a Regulator of a Breach of Confidential Information where such failure to notify is in violation of any law.

#### 3.10 War and Terrorism

Any war (whether war is declared or not), terrorism (except Cyber Terrorism), invasion, use of military force, civil war, popular or military rising, rebellion or revolution, or any action taken to hinder or defend against any of these events.

---

## Digital Media Content Liability Coverage

### 1. Insurance Covers

#### 1.1 DIGITAL MEDIA CONTENT LIABILITY

The Insurer will pay, on behalf of each Insured, Loss resulting from a Claim first made during the Policy Period arising from Digital Media Activities.

### 2. Definitions

The following definitions are specific to this Digital Media Content Liability Coverage Section. All other definitions set out within Section 9 (Definitions) of the General Terms and Conditions shall apply as stated.

#### BREACH OF CONFIDENTIAL INFORMATION

The unauthorised access to or unauthorised disclosure of Confidential Information.

#### CLAIM

(i) A written demand against an Insured; or

(ii) civil, administrative or arbitral proceedings brought against an Insured,

seeking any legal remedy for a Wrongful Act.

#### DAMAGES

Damages that an Insured is legally liable to pay resulting from a Claim as ascertained by:

(i) judgments or arbitral awards rendered against that Insured;

(ii) monies payable by that Insured pursuant to any settlement agreement negotiated by that Insured and for which prior written consent has been obtained from the Insurer.

Damages includes punitive or exemplary or multiple Damages where lawfully insurable.

#### DEFENCE COSTS

Reasonable and necessary fees, costs and expenses which an Insured incurs with the prior written consent of the Insurer, in relation to the investigation, response, defence, appeal or settlement of a Claim, including court attendance costs incurred by or on behalf of that Insured.

Defence Costs does not include the remuneration of any Insured, cost of their time or any other costs or overheads of any Insured.

#### DIGITAL MEDIA ACTIVITIES

The posting on the Company's website or social media outlets, of any Digital Media.

#### DIGITAL MEDIA

Any digitised content, including text, graphics, audio and video, that can be transmitted over the internet or computer networks.

#### INSURED

(i) A Company;

(ii) a natural person who was, is or during the Policy Period becomes a principal, partner, director, officer or Employee of a Company;

(iii) an independent contractor, temporary contract labourer, self–employed person or labour–only subcontractor, under the direction and direct supervision of a Company, but only in relation to the Digital Media Activities they undertake for that Company;

(iv) a joint venture where a Company maintains operational control, but only to the extent of the Company's interest in such joint venture; and

(v) a natural person or entity which a Company is required by contract to add as an Insured under this policy, but only when and to the extent such natural person is acting on behalf of that Company;

provided that such organisation or person shall only be covered under this Digital Media Content Liability Coverage Section in respect of Loss arising from a Wrongful Act when undertaking Digital Media Activities in the foregoing capacities.

Insured includes the estate, heirs or legal representatives of a deceased, legally incompetent or bankrupt Insured referred to in (ii) above to the extent that a Claim is brought against them solely by reason of them having an interest in property that is sought to be recovered in a Claim against such Insured referred to in (ii) above.

#### INSURED EVENT

A Claim.

#### INTELLECTUAL PROPERTY

Copyright, trademark, service mark, design rights, know-how, database rights, registered domain or any other Intellectual Property, but not including patents or trade secrets.

#### LOSS

Damages and Defence Costs;

Loss does not include:

(i) non–compensatory or multiple Damages (except to the extent covered as Damages) or liquidated Damages;

(ii) fines or penalties;

(iii) the costs and expenses of complying with any order for, grant of or agreement to provide injunctive or other non–monetary relief;

(iv) discounts, service credits, rebates, price reductions, coupons, prizes, awards or other contractual or non–contractual incentives, promotions or inducements offered to an Insured's customers or Clients;

(v) production costs or the cost of recall, reproduction, reprinting, return or correction of Digital Media by any person or entity; or

(vi) any Insured's remuneration, cost of time or overheads.

#### WRONGFUL ACT

Any actual or alleged:

(i) defamation, including libel, slander, disparagement of trade reputation or the character of any person or organisation, or infliction of emotional distress or mental anguish arising from the foregoing;

(ii) unintentional infringement of copyright, title, slogan, trademark, trade name, trade dress, mark, service mark, service name, or domain name;

(iii) plagiarism, piracy or misappropriation or theft of ideas or information;

(iv) invasion, infringement or interference with rights of privacy, publicity, morals, false light, public disclosure of private facts, intrusion and commercial appropriation of name, persona or likeness; or

(v) passing-off but only if alleged in conjunction with any of the acts listed in (i) – (iv) above,

on or after the Retroactive Date and prior to the end of the Policy Period in the course of undertaking Digital Media Activities.

### 3. Exclusions

The following Exclusions are specific to this Security and Privacy Liability Coverage Section. They apply in addition to the Exclusions in Section 10 (Exclusions) of the General Terms and Conditions.

The Insurer shall not be liable for Loss arising out of, based upon or attributable to:

#### 3.1 ANTI–TRUST

Any actual or alleged antitrust violation, restraint of trade, unfair competition or unfair or deceptive business practices, including violation of any consumer protection law.

#### 3.2 ASSUMED LIABILITY, GUARANTEE, WARRANTY

Any:

(i) guarantee or express warranty made by an Insured; or

(ii) contractual liability or other obligation assumed or accepted by an Insured.

#### 3.3 BODILY INJURY AND PROPERTY DAMAGE

Any:

(i) physical injury, mental illness, sickness, disease or death; or

(ii) damage to or loss of or destruction of tangible property or loss of use thereof.

#### 3.4 EMPLOYMENT PRACTICES LIABILITY

Any of a Company's employment practices (including wrongful dismissal, discharge or termination, discrimination, harassment, retaliation or other employment-related Claim).

#### 3.5 FINANCIAL DATA

Any:

(i) misleading, deceptive or fraudulent financial Data; or

(ii) errors made in any financial Data,

that the Company publicises including the Company's annual report and accounts and any communications to the stock market.

#### 3.6 GOODS, PRODUCTS OR SERVICES

Any:

(i) false advertising or misrepresentation in advertising of a Company's products or services;

(ii) any failure of goods, products or services to conform with an advertised quality or performance; or

(iii) infringement of trademark, trade name, trade dress, mark, service mark or service name by any goods, products or services displayed or contained in any Digital Media.

#### 3.7 GOVERNMENT/REGULATORY ACTION

Any government, regulatory, licensing or commission action or investigation.

#### 3.8 INFRASTRUCTURE

Any:

(i) mechanical failure;

(ii) electrical failure, including any electrical power interruption, surge, brownout or blackout; or

(iii) telecommunications failure.

#### 3.9 INSURED V INSURED

Any Claim brought by or on behalf of an Insured against another Insured except a Claim by an Insured which directly results from another Claim by a Third Party first made during the Policy Period and covered by this Digital Media Content Liability Coverage Section.

#### 3.10 INTENTIONAL INFRINGEMENT OF INTELLECTUAL PROPERTY

Any intentional infringement of Intellectual Property.

#### 3.11 INTERNAL MESSAGING SERVICES

Any publication or broadcast of Digital Media posted or transmitted on any of the Company's internal instant message system, intranet, messaging boards, or chat rooms.

#### 3.12 OVER-REDEMPTION

Any price discounts, prizes, awards or other consideration given in excess of the total contracted or expected amount.

#### 3.13 OWNERSHIP RIGHTS

Any Claim against the Company brought by or on behalf of any independent contractor, third-party distributor, licensee, sub-licensee, joint venture, venture partner, any Employee of the foregoing, or any Employee or agent of the Company arising out of, based upon or attributable to disputes over:

(i) the ownership or exercise of rights in Digital Media; or

(ii) services supplied by such independent contractor, third-party distributor, licensee, sub-licensee, joint venturer, venture partner or Employee or agent.

#### 3.14 PATENT/TRADE SECRET

Any:

(i) infringement of patents;

(ii) Loss of rights to secure registration of patents; or

(iii) misappropriation of trade secrets.

#### 3.15 ROYALTIES AND OTHER MONIES

Any:

(i) accounting or recovery of profits, royalties, fees or other monies claimed to be due from an Insured; or

(ii) licensing fees or royalties ordered, directed or agreed to be paid by an Insured pursuant to a judgment, arbitration award, settlement agreement or similar order or agreement, for the continued use of a person or entity's copyright, trademark, service mark, design rights, know-how, database rights, registered domain or any other Intellectual Property.

#### 3.16 SECURITIES CLAIMS

Any:

(i) actual or alleged violation by an Insured of any law, regulation or rule relating to the ownership, purchase, sale or offer of, or solicitation of an offer to purchase or sell, Securities;

(ii) any actual or alleged violation by an Insured of any provision of the Securities Act of 1933, the Securities Exchange Act of 1934 (each a United States of America statute) or any similar law of any jurisdiction; or

(iii) any actual or alleged violation by an Insured of the Racketeer Influenced and Corrupt Organisation Act 18 USC Section 1961 et seq (a United States of America statute) and any amendments thereto or any Rule or Regulation promulgated thereunder.

#### 3.17 Trade Debts

Any:

(i) trading debt incurred by an Insured; or

(ii) guarantee given by an Insured for a debt.

#### 3.18 Trading Losses/Monetary Value

Any trading Losses or trading liabilities, monetary value of any electronic fund transfers or transfers by or on behalf of an Insured.

#### 3.19 War and Terrorism

Any war (whether war is declared or not), terrorism, invasion, use of military force, civil war, popular or military rising, rebellion or revolution, or any action taken to hinder or defend against any of these events.

---

## Cyber Extortion Coverage

### 1. Insurance Covers

#### 1.1 CYBER EXTORTION

The Insurer will pay, to or on behalf of each Company, Loss that the Company incurs solely as a result of an Extortion Threat which first occurs during the Policy Period.

### 2. Definitions

The following definitions are specific to this Cyber Extortion Coverage Section. All other definitions set out within Section 9 (Definitions) of the General Terms and Conditions shall apply as stated.

#### BREACH OF CONFIDENTIAL INFORMATION

The unauthorised access to or unauthorised disclosure of Confidential Information.

#### COMPANY COMPUTER SYSTEM

(i) Any computer hardware, software or any components thereof that are linked together through a network of two or more devices accessible through the internet or an intranet or that are connected through Data storage or other peripheral devices which are owned, operated, controlled or leased by a Company;

(ii) any of the foregoing computer hardware, software or components thereof which is part of an industrial control system, including a supervisory control and Data acquisition (SCADA) system; or

(iii) any Employee "Bring Your Own Device" but only to the extent such device is used to access any of the foregoing computer hardware, software or components thereof or Data contained therein.

#### CONFIDENTIAL INFORMATION

Corporate Information and Personal Information in a Company's or Information Holder's care, custody or control or for which a Company is legally responsible.

#### CORPORATE INFORMATION

A Third Party's items of information that are not available to the public (including trade secrets, Data, designs, forecasts, formulas, practices, processes, records, reports and documents) which are subject to contractual or legal protection.

#### CYBER EXTORTION EXPENSES

The reasonable and necessary fees, costs and expenses of any firm appointed by the Insurer or any other firm appointed by the Company that has been approved by the Insurer in advance of such appointment to provide the Cyber Extortion Services.

#### CYBER EXTORTION SERVICES

(i) Conducting an investigation to determine the validity, cause and scope of an Extortion Threat;

(ii) advising on the response to an Extortion Threat;

(iii) containing or resolving the disruption of the operations of a Company Computer System caused by the Extortion Threat; or

(iv) assisting a Company in negotiating a resolution to an Extortion Threat.

#### CYBER TERRORISM

The premeditated use of disruptive activities against a Company Computer System or network, or the explicit threat to use such activities, by an individual or group of individuals, whether acting alone or on behalf of or in connection with any entity or government, in each case with the intention to cause harm, further social, ideological, religious, political or similar objectives, or to intimidate any person(s) in furtherance of such objectives.

Cyber Terrorism does not include any such activities which are part of or in support of any use of military force or war.

#### EXTORTION THREAT

Any threat or connected series of threats made to the Company, for the purpose of demanding payment or transfer of Money, Securities or other tangible or intangible property of value from a Company, to:

(i) commit or continue a Breach of Confidential Information;

(ii) commit or continue an intentional attack against a Company Computer System (including through the use of ransomware); or

(iii) disclose information concerning a vulnerability in a Company Computer System.

#### INFORMATION HOLDER

A Third Party that holds Personal Information or Corporate Information on behalf of a Company.

#### INSURED

A Company.

#### INSURED EVENT

An Extortion Threat.

#### LOSS

(i) Any payment of cash, monetary instrument, Cryptocurrency (including the costs to obtain such Cryptocurrency) or the fair market value of any property which a Company has paid, to prevent continuation of, or end, an Extortion Threat; and

(ii) Cyber Extortion Expenses.

#### PERSONAL INFORMATION

Any information relating to an identified or identifiable natural person.

Personal Information includes a natural person's name, national registration identification number, telephone number, credit card or debit card number, account and other banking information, medical information, or any other information about a natural person protected under any Data Protection Legislation.

### 3. Exclusions

The following Exclusions are specific to this Cyber Extortion Coverage Section. They apply in addition to the Exclusions in Section 10 (Exclusions) of the General Terms and Conditions.

The Insurer shall not be liable for any Loss:

#### 3.1 ANTI-TERRORISM LEGISLATION

To the extent that the provision of such payment to or on behalf of a Company would expose the Insurer, its parent Company or its ultimate controlling entity to any applicable anti-terrorism legislation or regulation under United Nations resolutions, and laws or regulations of the European Union, or the United States of America or the United Kingdom.

#### 3.2 BODILY INJURY AND PROPERTY DAMAGE

For any:

(i) physical injury, mental illness, sickness, disease or death; or

(ii) loss, damage or destruction of tangible property.

#### 3.3 GOVERNMENT ENTITY OR PUBLIC AUTHORITY

Arising out of, based upon or attributable to a regulatory or enforcement threat or demand by any government entity or public authority.

#### 3.4 PATENT

Arising out of, based upon or attributable to any infringement of patents.

#### 3.5 WAR AND TERRORISM

Arising out of, based upon or attributable to any war (whether war is declared or not), terrorism (except Cyber Terrorism), invasion, use of military force, civil war, popular or military rising, rebellion or revolution, or any action taken to hinder or defend against any of these events.

---

## Cyber Crime Coverage

### 1. Insurance Covers

#### 1.1 IMPERSONATION FRAUD COVERAGE

The Insurer will pay, to or on behalf of each Company, Impersonation Fraud Loss incurred as a result of an Insured Event which is Discovered by the Insured during the Policy Period.

#### 1.2 FUNDS TRANSFER FRAUD COVERAGE

Cover provided under this Insurance Cover 1.1 shall be subject to the condition that the Fraudulent Instruction was Verified prior to the Impersonation Fraud Loss.

#### 1.3 
