.

Chair, Privacy and Data Security

Chair, Intellectual Property, Technology and Media Litigation

Portrait of David J. Shannon

Defense Digest

Kaseya Data Breach Is Another Signal to Cyber Underwriters About the Dangers of Ransomware Attacks

Defense Digest, Vol. 27, No. 4, September 2021

September 1, 2021

by David J. Shannon

Key Points:

  • Cyber underwriters working with managed service providers need to fully evaluate a company’s computer systems, the vendors and suppliers they use, the number of customers they have, and the number of endpoints these customers have.
  • Cyber underwriters would be well advised to develop policies that will examine the key areas of a managed service provider’s supply chain.

In early July, Kaseya, a software supplier based in Miami, Florida, was the victim of a sophisticated ransomware attack. This attack was even more damaging because the hackers targeted an IT management software supply vendor. Kaseya provides software as a service (SaaS) and virtual server administrator systems (VSA) to numerous managed service providers (MSP). The MSPs use Kaseya’s software systems to assist with their numerous business customers in implementing and managing their computer systems.

The Kaseya data breach was purportedly carried out by the hacking group Revil. The ransomware virus was injected into a Kaseya software update that was sent to its customers. A chain of events then occurred where the virus infected the MSPs and then numerous business clients of the MSPs. Several thousand businesses (likely to increase) have been impacted and found most or all of their computer systems encrypted.

The cyber claims for this will be significant. All of the businesses will be making claims for first-party data breach response expenses. In addition, it is likely that third-party claims against the MSPs will also be occurring in the near future.

Cyber underwriters should learn from this exploitation breach, as well as earlier supply chain breaches, like Solar Winds, that a breach of one insured, particularly an MSP, can lead to significantly more companies being impacted and significantly more claims, risks and expenses. Underwriters working with MSPs need to fully evaluate a company’s computer systems, the vendors and suppliers they use, the number of customers they have and the number of endpoints these customers have. A forensic exam always begins with determining the total number of endpoints, i.e. servers, workstations or other computer systems, that will need to be reviewed, potentially cleaned and undergo remediation services.

 While the cyber policy may be written simply for the MSP insured, the claims that could arise in the future will be for the dozens, if not hundreds, of customers the MSP insured works with. Cyber underwriters would be well advised to develop policies that will examine the key areas of an MSP’s supply chain. The business security practices, supply chain, system controls, backup and siloing, or containment, of different systems must be reviewed to determine the full risk that exists. While both the third-party computer system providers and their end users must develop a mindset of security and containment, cyber underwriters must also be evermore vigilant in determining whether these practices have been implemented and determine the full effect if a supply chain attack occurs.

*David is a shareholder and chair of both the Privacy and Data Security Practice Group and the Intellectual Property, Technology and Media Litigation Practice Group. He may be reached at djshannon@mdwcg.com.

Defense Digest, Vol. 27, No. 4, September 2021 is prepared by Marshall Dennehey Warner Coleman & Goggin to provide information on recent legal developments of interest to our readers. This publication is not intended to provide legal advice for a specific situation or to create an attorney-client relationship. ATTORNEY ADVERTISING pursuant to New York RPC 7.1. © 2021 Marshall Dennehey Warner Coleman & Goggin. All Rights Reserved. This article may not be reprinted without the express written permission of our firm. For reprints, contact tamontemuro@mdwcg.com.

Firm Highlights

Thought Leadership

Appellate Division Affirms Dismissal of Legal Malpractice Counterclaim Against Martin Law Firm

In Martin v. Loury, 2026 N.J. Super. Unpub. LEXIS 1617 (App. Div. July 15, 2026), Martin Law Firm represented Kirk Loury in an employment matter Mr. Loury filed against his former employer, Concord Equity Group Advisors LLC (“Concord”). The allegations included, among other things, that Loury was not fairly compensated for his employment with Concord. After a bench trial finding in Loury’s favor, the Appellate Division remanded this matter in February 2016 for a second trial. During the second trial, Concord CEO, Lee Argush, testified to lower compensation estimate than first trial. On remand, the second trial judge awarded Mr. Loury the same damages as the first judge, finding Mr. Argush not credible. After the findings during the second trial, Martin Law Firm filed an action against Mr. Loury to recover legal fees and costs of representing Mr. Loury in a second bench trial and Mr. Loury filed a counterclaim against Martin Law Firm for legal malpractice, alleging he should have received an even higher award in the second bench trial. In this allegation, Mr. Loury, through his expert, claimed that Martin Law Firm should have recalled Mr. Loury to the stand to rebut Mr. Argush’s testimony to allege an alternative theory of damages. Mr. Loury’s expert admitted that the second judge already rejected Mr. Argush's theory and accepted Loury's damages theory. The trial court barred Mr. Loury’s expert and dismissed Loury's counterclaim with prejudice before convening the collection trial, and the jury ruled in Martin Law Firm’s favor. Mr. Loury appealed the trial court's pretrial rulings barring his liability expert from testifying in support of his legal malpractice counterclaim, denying his motion for summary judgment on that counterclaim, and denying his motion to amend his counterclaim by adding attorney Joseph A. Martin as a codefendant. In affirming the trial court’s decision, the Appellate Division held that the trial court properly excluded Loury’s expert testimony in the counterclaim against Martin Law Firm because the expert could not explain how calling Loury as a rebuttal witness would have increased damages when the second judge already rejected Mr. Argush's testimony and accepted Loury's damages theory, making the expert’s causation opinion speculative. The Appellate Division also held that the trial court properly denied Mr. Loury's summary judgment motion on his malpractice counterclaim because reasonable minds could differ on whether Mr. Martin's alleged failures would have changed the second judge's damages award, given the judge already found Mr. Argush not credible, creating genuine factual disputes precluding summary judgment. Also, the Appellate Division held that the trial court properly denied Loury's May 2023 motion to add Joseph Martin individually because the statute of limitations expired in February 2022, six years after the 2016 appellate remand when Mr. Loury incurred new legal costs, and relation back did not apply because Mr. Loury knew Mr. Martin's identity throughout and strategically chose to sue only Martin Law Firm in his 2019 counterclaim.