The essentials
- Notify the insurer immediately — late notice is among the most common reasons cyber claims are reduced or denied.
- Many policies require approved ("panel") vendors for response and forensics; hiring your own first can leave those costs uncovered.
- Document from hour zero: costs, hours, decisions, and business impact. Claims are paid on evidence, not narrative.
- Do not admit liability, settle with third parties, or authorize extortion payments without insurer involvement — each can void parts of coverage.
- Read the policy tonight with counsel: sublimits, exclusions, and waiting periods shape response strategy more than most teams expect.
Cyber insurance behaves less like a safety net and more like a contract with choreography: notice within defined windows, approved vendors, consent requirements for major decisions, and proof for every dollar claimed. None of it is hostile — but all of it punishes improvisation.
Ten minutes of process at the start of the incident routinely decides five or six figures at settlement.
Do this now
- Give notice now. Follow the policy's notice clause to the letter — the named contact, the required channel, in writing, timestamped. When in doubt whether the incident qualifies, notify anyway; provisional notice is cheap and late notice is not.
- Ask about panel requirements. Before engaging forensics, counsel, or negotiators, confirm whether the policy requires approved vendors — and get any exception you need agreed in writing.
- Open the ledger. One running record: response costs, internal hours, replacement purchases, downtime and lost-revenue estimates, all with receipts and timestamps. Assign it an owner today.
- Loop the insurer into big decisions. System rebuilds versus restores, customer notifications, any extortion negotiation — insurers expect consultation on decisions that drive claim size, and consent clauses often require it.
- Preserve the proof. Forensic findings, incident timeline, and evidence of what happened are also claim substantiation — the same discipline that serves the investigation serves the payout.
- Map the policy to the incident. With counsel, read the operative sections: what is covered (response, business interruption, liability, extortion), at what sublimits, with which exclusions and waiting periods. Strategy follows the map.
What not to do
- Do not delay notice while you "figure out how bad it is" — that is what provisional notice is for.
- Do not hire off-panel vendors blind if the policy names a panel.
- Do not admit fault to third parties or settle side deals without the insurer.
- Do not authorize any extortion payment without insurer and counsel sign-off — sanctions exposure and coverage both hang on it.
- Do not reconstruct costs from memory at claim time; the contemporaneous ledger is the difference.
Preserve the evidence
Whatever else happens, these are the artifacts the investigation — and any insurance claim, dispute, or prosecution — will be built from:
- The policy and the timestamped notice correspondence.
- The running cost and impact ledger with receipts.
- Vendor approvals and insurer consents, in writing.
- Forensic reports and the incident timeline.
Keep a clear head
Mid-incident, insurer process feels like bureaucracy taxing a crisis. Reframe it: the insurer is the party that eventually reimburses this nightmare, and every consent and receipt is a brick in that claim. The teams that treat the claim as part of the incident — not an afterthought — are the ones made whole.
Questions victims ask
Does cyber insurance cover ransom payments?
Many policies include extortion coverage, always with conditions: insurer consent, legal review (sanctions), and often a specialist negotiator. Paying without consent can forfeit that coverage entirely — which is one more reason payment is never a solo decision.
What gets cyber claims denied in practice?
Late notice, off-panel vendors without approval, unmet security warranties (the MFA you attested to but didn't deploy), excluded event categories, and costs without documentation. Most of that list is avoidable with the first-day process above.
Will claiming spike our premium?
Renewal pricing follows both the claim and what you fixed afterward. A documented incident with credible remediation often lands better than insurers' fear of the unremediated. Budget for hardening in the recovery plan — it pays twice.