A suspicious payment has gone to the wrong bank account. Staff suddenly lose access to critical systems. A customer database may have been compromised. When a cyber incident reaches that point, the priority is not to establish every detail before acting. It is to contain the problem, preserve evidence and start the insurance response quickly.
A cyber insurance claim can develop differently from a conventional property or liability claim. The insurer may need forensic investigators, legal advisers, incident-response specialists or other experts involved while the event is still unfolding. Decisions made in the first few hours can therefore affect both recovery and the evidence available later.
For UK businesses, knowing what to do before an incident happens makes the process far easier to manage when systems, money or sensitive information are already at risk.
What should you do first after a cyber incident?
The first response should focus on preventing further harm without destroying information that may be important to the investigation.
Where practical, affected devices, accounts or systems may need to be isolated from the wider network. However, avoid automatically wiping devices, deleting files, clearing logs or rebuilding systems before appropriate technical advice has been obtained. Those actions can remove evidence needed to establish how the incident occurred and what was affected.
Your IT team or provider may need to act immediately to secure the environment, but the response should be controlled rather than improvised.
At the same time, begin an incident record.
Note:
- When the problem was first identified
- Who discovered it
- Which accounts, devices or systems appear to be affected
- What unusual activity has been seen
- Any suspicious emails or payment instructions
- What action has already been taken
- Who has been contacted
- When important decisions were made
Keep relevant emails, screenshots, invoices, transaction details and system information where possible.
The purpose is not to create a perfect technical report in the first hour. It is to establish a reliable timeline while events are still fresh.
Notify the insurer or broker before you know the full picture
Businesses sometimes delay notification because they do not yet know exactly what happened.
That can be a mistake.
Cyber policies may require incidents or circumstances to be reported promptly, particularly where there is ransomware, suspected data compromise, system interruption or a potentially fraudulent payment.
You do not normally need a completed forensic investigation before making the initial notification.
Be ready to explain:
- What happened or appears to have happened
- When it was discovered
- Whether the incident is continuing
- Which systems or services may be affected
- Whether money appears to have been lost
- Whether personal or commercially sensitive information may be involved
- What immediate containment steps have been taken
Stick to the facts that are known. If something is uncertain, say so rather than trying to fill the gaps.
Where the incident involves a fraudulent transfer, contact the relevant bank immediately as well. Speed can matter where an attempt is being made to trace or recover transferred funds.
A technology-enabled fraud does not automatically mean the financial loss sits under a cyber policy. Depending on how the loss occurred and the cover arranged, the claim may involve cyber insurance, crime insurance or both. The distinction is particularly important with fraudulent payment and social engineering losses.
What happens after a cyber insurance claim is reported?
The precise process depends on the insurer, policy and type of incident, but a cyber claim will often move through several stages.
Initial notification and triage
The insurer or broker receives the first account of the incident and identifies what immediate support may be required.
The business may be asked for further information about affected systems, the suspected cause, any loss of money, operational disruption and the steps already taken.
At this stage, the priority is usually understanding the urgency rather than quantifying the final claim.
Specialist incident response
Depending on the policy and incident, specialists may be appointed to help investigate and manage the event.
These could include:
- Digital forensic investigators
- Cyber incident-response specialists
- Legal advisers
- Data breach specialists
- Crisis communications advisers
- Ransomware or extortion specialists
- Claims handlers or adjusters
Not every incident requires every specialist.
A business email compromise affecting one account will need a different response from a ransomware event affecting several sites and critical systems.
Investigation and containment
Forensic specialists may investigate how access was gained, whether the attacker remains in the environment, which systems were affected and whether information was accessed or removed.
That work can also influence the recovery strategy.
Restoring systems quickly is important, but restoring a compromised environment without understanding how the attacker gained access can create another problem. The investigation and recovery plan therefore need to work together.
Recovery and temporary operations
Once the immediate threat is better understood, attention moves towards restoring systems and keeping the business operating.
That may involve recovering from backups, rebuilding affected environments, introducing temporary systems or finding alternative ways to deliver services.
Keep records of these decisions and their costs as the recovery develops.
Loss assessment
The financial side of the claim can continue long after systems are functioning again.
The business may need to evidence interruption losses, additional expenditure, professional costs and other insured losses arising from the incident.
Policy and claim assessment
The insurer will consider the circumstances against the policy wording, including relevant limits, sub-limits, excesses, conditions and exclusions.
A complicated cyber incident may involve several different parts of the policy, so the final position may develop as the forensic and financial evidence becomes clearer.
Use the specialists available under the policy
One of the most important differences between cyber insurance and many traditional insurance policies is the incident-response support that may be available while the event is happening.
A well-structured cyber insurance policy may give the business access to specialists who regularly deal with cyber incidents.
Businesses should therefore be cautious about immediately appointing outside advisers, instructing a new forensic firm or committing to substantial recovery expenditure without first checking the policy requirements where circumstances allow.
Some policies may require particular panel providers to be used or insurer approval before certain costs are incurred.
That does not mean a business should allow damage to continue while waiting for permission to act. Urgent containment may still be necessary. The point is to involve the insurer or broker early enough that emergency response and insurance requirements remain aligned.
Keep detailed evidence of business interruption
Cyber claims can become financially significant because of the disruption that follows the technical incident.
A business may lose access to order systems, customer records, accounting software, manufacturing controls, warehouse systems or communication platforms.
The claim therefore needs more than a record showing that a server was unavailable.
Keep evidence of the actual commercial effect, including:
- Lost or cancelled orders
- Delayed projects
- Missed appointments
- Production downtime
- Additional staff hours
- Overtime
- Temporary software or equipment
- External IT expenditure
- Alternative premises or operating arrangements where relevant
- Additional supplier costs
- Other reasonable expenditure incurred to reduce disruption
Finance teams should retain management accounts, forecasts, sales records and other information that can help establish what the business would reasonably have expected to achieve without the incident.
The way a cyber business interruption claim is calculated will depend on the policy wording and the circumstances of the loss. The important point during the incident is to preserve the financial evidence rather than trying to reconstruct it months later.
Treat possible data exposure separately from system downtime
A cyber incident can create several problems at once.
Systems may be unavailable while personal data, confidential correspondence or commercially sensitive information is also potentially exposed.
Do not assume that information has definitely been stolen simply because an attacker gained access. Equally, do not assume that no data has been affected because systems have been restored successfully.
The forensic investigation may be needed to establish what was accessed and what evidence exists.
Where sensitive information may be involved, legal and specialist advice can help determine what further action is appropriate. Depending on the circumstances, the business may need to consider communications with customers, employees, suppliers, regulators or other affected parties.
External statements should be based on established facts wherever possible.
Saying too much before the position is understood can create unnecessary confusion. Saying too little for too long can create a different set of problems.
Take extra care with ransomware and extortion
Ransomware creates pressure precisely because attackers want decisions to be made quickly.
Systems may be encrypted, information may have been copied and deadlines may be imposed alongside demands for payment.
Do not assume paying will restore the business or guarantee that stolen information will not be used.
Where a ransomware incident is involved, insurers and specialist response teams may need to consider the technical position, available backups, the credibility of the attacker, possible data theft and any legal or policy restrictions relevant to the response.
Businesses should avoid independently negotiating, promising payment or transferring funds without appropriate specialist involvement.
The immediate objective is to understand the available recovery routes rather than allow the attacker to dictate the response timetable.
What can make a cyber insurance claim harder?
Cyber claims are often complicated because evidence, systems and financial losses continue to change while the claim is being handled.
Several avoidable actions can make that process more difficult.
Waiting too long to notify the insurer
You do not need to know the final cost or exact technical cause before reporting a serious incident.
Early notification allows the insurer to identify what support is available and what information should be preserved.
Deleting logs or rebuilding systems too quickly
Restoration matters, but removing evidence before the cause and extent of the incident are understood can make forensic investigation more difficult.
Incurring major costs without checking the policy
Where the situation allows, check whether insurer approval or the use of nominated providers is required before committing to substantial expenditure.
Failing to document financial losses as they occur
The longer a business waits to record cancelled sales, downtime and additional expenditure, the harder it can become to establish the true financial impact.
Giving different versions of the incident
The facts may change as the investigation develops, but the underlying timeline should remain clear.
Maintain one central incident record and update it when new evidence becomes available.
Assuming every cyber-related loss is insured
A cyber event can produce several types of loss.
For example, fraudulent payments, ransom demands, lost income and third-party claims may each sit under different sections, sub-limits or policies.
The existence of a cyber policy does not mean every cost arising from the event will automatically be covered.
A cyber claim needs one clear internal lead
Large incidents can quickly involve directors, IT, finance, legal advisers, insurers, external specialists and communications teams.
That makes internal coordination important.
Nominate someone with responsibility for keeping the incident record, coordinating requests for information and making sure key decisions are documented.
That person does not have to make every decision themselves. Their role is to stop important information becoming scattered across emails, messages and separate teams.
Finance should record costs.
IT should maintain technical evidence.
Senior management should understand the operational priorities.
External communications should be controlled.
The insurer and appointed specialists should receive consistent information.
A clear structure makes the response easier to manage when pressure is increasing.
Prepare the claims process before an incident happens
The worst time to discover how the cyber policy works is when nobody can access the network.
Keep essential insurance information available somewhere that does not depend entirely on the systems being insured.
That should include:
- Policy details
- Insurer or broker contact information
- Cyber incident hotline details where provided
- Key internal contacts
- IT provider details
- Banking contacts
- Authority levels for urgent expenditure
- Roles for senior management, finance and communications
Businesses should also know who has authority to notify the insurer and who would lead the response outside normal working hours.
Testing those arrangements can expose very simple problems. A response plan is not much use if the only copy is stored on a server that has just been encrypted.
Cyber cover should also be reviewed as the business changes. New systems, acquisitions, cloud platforms, payment processes and larger contracts can alter both the likelihood of an incident and the scale of a possible claim.
A clear process makes recovery easier
A cyber claim rarely begins with a neat explanation of what happened.
The business may initially know only that money has disappeared, systems have stopped working or suspicious activity has been found.
That is enough to start taking sensible action.
Contain the incident without unnecessarily destroying evidence. Record the facts. Notify the insurer or broker early. Use the specialist support available. Document operational and financial losses as they develop, and keep one clear record of the response.
The technical position may take time to understand and the final insurance claim may take longer still. A disciplined response from the first hours gives both the business and its insurer a much stronger foundation for managing what comes next.
FAQs About Cyber Insurance Claims
Should a cyber incident be reported if there has not been a financial loss yet?
Potentially, yes. Some policies require notification of circumstances that could later lead to a claim, even where the financial impact is not yet known. The notification terms should be checked rather than waiting for a confirmed loss to develop.
Can a cyber claim involve more than one insurance policy?
Yes. An incident can create different types of loss, such as system damage, fraudulent payments or third-party allegations. Depending on the circumstances and cover arranged, more than one policy may need to be considered.
What happens if a cyber incident starts with an outsourced technology provider?
A business may still suffer its own interruption or financial loss even when the original incident occurs at a cloud provider, software supplier or managed IT service. Whether the resulting loss is insured will depend on the policy’s treatment of third-party technology providers.
Does a business need a police reference number for every cyber insurance claim?
Not necessarily. Reporting requirements depend on the type of incident and policy wording. Fraud, theft or other criminal activity may require reporting to the appropriate authority, while other cyber incidents may follow a different process.
Can a cyber insurance claim continue after systems have been restored?
Yes. Technical recovery does not necessarily end the claim. Financial losses, professional costs, third-party issues and other consequences may continue to develop after systems are back online.