Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Why Subrogation Claims Fail Before DiscoveryCyber Threats & Attacks
6 min readFor Cyber Insurance Buyers & Brokers

Why Subrogation Claims Fail Before Discovery

When your insurer pays a claim and wants to recover those dollars from the vendor whose failure caused the breach, you'd think the path forward would be straightforward. It isn't. The Delaware Supreme Court's reversal of a lower court dismissal in the Blackbaud case reveals how insurers routinely stumble over procedural hurdles that have nothing to do with the merits of their recovery claims.

Why These Mistakes Keep Happening

Subrogation in cyber insurance operates in unfamiliar territory. Most case law comes from property and auto claims, where causation is clearer and damages are easier to quantify. When insurers step into their insureds' shoes to pursue a vendor after a data breach, they're dealing with contract law, cybersecurity standards, and aggregated claims across multiple clients. The procedural missteps aren't about weak facts. They're about misunderstanding what courts need to see at the pleading stage versus what belongs in discovery.

Mistake 1: Treating Aggregated Claims Like Individual Lawsuits

Why it happens: When multiple insureds suffer losses from the same vendor failure, insurers assume they must plead each client's damages separately with granular detail. Aggregating claims feels risky because it seems like glossing over individual circumstances.

The consequence: You either file dozens of separate complaints (expensive, slow, duplicative) or you aggregate and face a motion to dismiss for insufficient specificity. The Superior Court in the Blackbaud matter dismissed aggregated claims, arguing the approach made it difficult for the defendant to mount a defense.

The fix: Aggregate strategically, but identify the common contractual duties and breaches that apply across all insureds. The Delaware Supreme Court confirmed that you don't need to detail each insured's response and expenses at the pleading stage. Establish that the vendor breached specific contract provisions (like maintaining current security measures or promptly investigating incidents) and that these breaches caused a category of damages (forensic costs, notification expenses, credit monitoring). Discovery is where you'll break out insured-by-insured details. Your complaint should name the contract terms violated, describe the breach pattern, and show that damages of a particular type resulted. Don't invent specificity you don't yet have.

Mistake 2: Confusing Proximate Cause With Strict Liability

Why it happens: Vendor contracts often include security obligations and mitigation provisions. Insurers read these as ironclad promises and assume any breach automatically makes the vendor liable for all downstream costs. When drafting complaints, they skip the causation analysis because the contract language seems clear enough.

The consequence: Courts dismiss your claim for failing to connect the vendor's specific failures to the insured's actual damages. The lower court worried that interpreting Blackbaud's mitigation provisions as imposing liability for every breach would create strict liability, which isn't the standard under New York contract law.

The fix: Under New York law (which governed the Blackbaud contracts), the breach must be a "substantial factor" in producing the damage. Don't just cite the contract provision. Explain why the insureds had no reasonable alternative but to incur the costs themselves. In the Blackbaud case, the insurers alleged that Blackbaud provided only a toolkit and shifted the investigative burden onto clients, forcing them to "fill the void." That's proximate cause: the vendor's inadequate response left insureds with no choice but to spend money on forensics, counsel, and notifications. Frame your causation argument around the insured's constrained options, not just the vendor's broken promise.

Mistake 3: Overloading the Complaint With Discovery-Level Facts

Why it happens: You want to demonstrate you've done your homework. You include detailed timelines, specific vendor communications, and itemized damages for each insured. It feels thorough.

The consequence: You invite the defendant to nitpick every detail and argue inconsistencies before you've had a chance to conduct discovery. Worse, you may inadvertently plead yourself out of claims by providing too much specificity that doesn't align perfectly across all insureds.

The fix: At the motion to dismiss stage, you need to raise a reasonable inference that damages were caused by the defendant. The Delaware Supreme Court noted that "damages may be pled generally" once you've alleged facts supporting causation. Identify the categories of costs (forensic analysis, breach notification, regulatory response) and tie them to the vendor's failures. Save the line-item breakdowns and insured-specific variances for discovery. If the defendant wants more detail about how each insured responded and what each spent, that's what interrogatories and depositions are for.

Mistake 4: Ignoring the Vendor's Public Contradictions

Why it happens: You focus on the contract and the breach. The vendor's public statements feel like a separate issue, maybe relevant for a securities claim but not for contract-based subrogation.

The consequence: You miss a powerful tool for establishing both breach and damages. Public misrepresentations can show that the vendor failed to meet its contractual disclosure and mitigation obligations, and they explain why insureds couldn't rely on the vendor's response.

The fix: Track the vendor's public timeline. Blackbaud told customers in July 2020 that no action was required and no personal information was accessed. In August, it dismissed concerns as hypothetical. By September, it disclosed in an SEC filing that unencrypted fields for bank account information and Social Security numbers may have been accessed. In 2023, Blackbaud paid a $3 million fine to the SEC for misleading disclosures and $49 million to resolve state claims. These contradictions support your causation argument: insureds couldn't trust the vendor's initial assurances and had to conduct independent investigations. Cite the public record to show the vendor's response was inadequate and untrustworthy.

Mistake 5: Failing to Anchor Claims in Specific Contract Provisions

Why it happens: Vendor agreements are long and contain overlapping security, notification, and indemnification clauses. Insurers reference "security obligations" generally without pinpointing which sections were breached.

The consequence: The defendant argues you haven't identified an actual breach, just a bad outcome. Courts may dismiss for failure to state a claim because you haven't connected specific contractual language to specific failures.

The fix: Identify each contractual duty by section and describe the corresponding breach. If the contract required the vendor to maintain current security measures, allege that it ignored warnings about vulnerabilities in remote desktop access and used obsolete servers. If the contract required prompt investigation and remediation, allege that the vendor provided only a toolkit instead of conducting its own forensic analysis. The Delaware Supreme Court noted that the insurers "identified each of Blackbaud's contractual duties and how Blackbaud allegedly breached those contractual provisions." That specificity survived the motion to dismiss. Your complaint should read like a checklist: duty, breach, consequence.

Prevention Checklist

Before filing your next subrogation claim after a vendor-caused breach, verify:

  • You've aggregated claims around common contractual breaches, not around identical damages
  • You've alleged proximate cause by showing insureds had no reasonable alternative to incurring costs themselves
  • You've pled damages generally by category, reserving insured-specific details for discovery
  • You've cited the vendor's public statements and regulatory actions to support inadequate response claims
  • You've anchored every breach allegation in a specific contract provision, not general security expectations
  • You've reviewed the governing law for contract claims (often New York) and confirmed your complaint meets each element
  • You've anticipated the defendant's argument that you're seeking strict liability and preemptively framed causation as substantial factor analysis

Subrogation in cyber insurance will only grow as insurers seek to recoup rising claims costs and hold vendors accountable. The procedural mistakes that derail these claims are avoidable. Focus on what courts need at the pleading stage, save the details for discovery, and anchor every allegation in contract language the vendor actually agreed to.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like