





10 Risk categories analyzed, though the inclusion of Natural Disaster Risk remains questionable
Risk Category Coverage Status Coverage Provider Risk Level (Tier-3) Action Required Equipment & Hardware Failures ✅ FULLY COVERED Manufacturer (3-yr warranty) LOW (quality hardware) ✅ No action needed Data Loss & Corruption ✅ FULLY COVERED Data Center Partner and its insurance company LOW (daily backups) ✅ No action needed Human Error & Negligence ✅ FULLY COVERED Data Center Partner and its insurance company LOW (professional staff) ✅ No action needed Theft & Security Breaches ✅ FULLY COVERED Data Center Partner and its insurance company VERY LOW (SOC2, 24/7 security) ✅ No action needed Supply Chain Disruptions - Initial Delivery ✅ FULLY COVERED None MEDIUM (single source vendors) ✅ Investigate supply chain insurance Facility-Related Risks (HVAC) ⚠️ PARTIALLY COVERED Data Center Partner and its insurance company VERY LOW (Tier-3 redundancy) ✅ Property insurance closes gap Software Bugs & Defects ⚠️ PARTIALLY COVERED Internal QA / Limited vendor MEDIUM (critical systems) ✅ Review E&O policy for software Regulatory & Compliance Fines ⚠️ PARTIALLY COVERED Data Center Partner and its insurance company (specific clauses) HIGH (evolving landscape) ✅ Expand D&O and E&O coverage Natural Disasters & Force Majeure ❌ NOT COVERED None LOW probability / HIGH impact ✅ Obtain servers only insurance but questionable whether needed provided Tier-3 Reputational Damage ❌ NOT COVERED None HIGH (social media impact) ✅ Consider PR crisis insurance