When a Data Center Goes Dark, Which Policy Responds?

By Anthony Manna

TThe data center boom is in full swing. The largest cloud and artificial intelligence (AI) companies are expected to spend roughly $750 billion on infrastructure this year, according to MIT Technology Review. More businesses than ever run on this infrastructure, including some that have no direct relationship with the operator.

When insuring data centers, significant risk management considerations go into the buildings themselves, as well as the software and systems inside them. But it’s also worth considering what a client stands to lose when those systems fail or get compromised.

The impact usually hits two lines of coverage at once: cyber and technology errors & omissions.

On the tech E&O side, it comes down to dependency. Customers build their own operations on top of a data center’s services, so when a service fails, their financial losses can be substantial. Those losses turn into claims. And since AI has driven tremendous growth in data center investments over the last year or two, the number of businesses depending on that capacity has climbed with it.

Cyber carriers worry more about concentration. Facilities keep getting bigger and more interconnected, and a single incident at one of them can interrupt operations for numerous businesses at the same time—for an underwriter, that is an aggregation problem as much as a cyber one.

Who is liable when an outage hits? It depends on the cause of the outage and which party caused the service failure. Contracts and hold harmless agreements obviously matter, since they can shift responsibility in directions the parties didn’t fully anticipate when they signed.

Finding the cause is often the slow part. Was it an attack, or a vendor’s error? Answering that question can take extensive forensic work, and forensic work isn’t cheap. Until someone can say what actually happened, nobody can say with much confidence whose policy should pay.

It gets tricky when a cyber incident causes a tech services failure. If an attack takes a data center offline and its customers suffer significant financial losses, the operator’s cyber policy may cover its own direct losses, while tech E&O may respond to claims from the customers the outage affected.

The problem is that this arrangement assumes both coverages agree on where one ends and the other begins. When the insuring agreements—or the policies, if they were placed separately—each point to the other, a gap remains. The data center sits in the middle, and its customers are still waiting to be made whole.

While writing both coverages on the same policy won’t settle every question, it takes much of the gray area off the table before a claim tests it.

How Vendors Complicate Matters

Delivering data center services can involve multiple software companies, technology vendors, infrastructure providers and professional services firms. Any of them can cause a failure. And even when it starts outside the operator’s walls, the operator may still owe obligations to its own customers.

Underwriters must look at third-party dependencies and at how contracts divide responsibility, then gauge how widely the financial impact of a single failure might spread. At that point, the exposure being underwritten belongs to several companies at once, and each must perform for the facility to stay operational.

Agents placing risks anywhere in the data supply chain—from data centers to vendors and software companies—should expect those questions and be ready to walk an underwriter through the client’s key vendor relationships.

Additionally, agents should review the client’s current professional lines program and understand how dependent their clients have become on data centers and outside tech providers—an agent can only address the exposures a client shares.

Agents should also review these coverage considerations:

  • Limits. Do they still fit? Consider higher limits for clients whose operations now run through this infrastructure.
  • AI-related wording. Take note of anything referring to AI in the forms, exclusions or enhancements, and understand what it actually does.
  • Dependent business interruption. Does this component of the cyber liability policy adequately address an outage involving a third party?
  • Contractual obligations. For tech service clients, the tech E&O policy must be measured against their contracts. Compare it with their contractual commitments and the losses their customers could suffer, and make sure the services they are contracted to perform fall within the policy’s definitions.

Ultimately, the insurance program has to keep pace with how the business operates today. A client that bought insurance coverage before moving critical operations onto a third-party data center may be carrying a program written for a different company.

For the most part, which policy responds when a data center goes dark gets settled long before the outage—in the insuring agreements and definitions agreed to at placement and in the contracts sitting behind them. Reviewing those now gives an agent the chance to close a gap while it is still a renewal conversation. After an outage, that same gap turns into a coverage dispute.

Anthony Manna is executive vice president, professional lines at Jencap.