Cyber Insurance and Incident Response: What to Do Before You Claim
Cyber insurance can be the difference between a bad week and a business-ending event. But a policy only pays out if you use it correctly, and the mistakes that reduce or void a claim are almost always made in the first few hours of an incident, by people acting fast and in good faith. Knowing your policy before you need it is one of the cheapest forms of protection there is.
This guide explains what to do, and what to avoid, so that your cyber insurance actually helps when the time comes. It is a companion to our full cyber incident response plan guide and pairs with our cyber insurance readiness guide.
Read your policy before there is an incident
The single most useful thing you can do is understand your policy while everything is calm. Cyber policies vary enormously, and several common terms directly affect how you should respond:
- Many policies require you to notify their incident line early, sometimes within a set number of hours of becoming aware.
- Many require you to use their approved responders (an incident-response panel), and engaging your own help first can reduce or invalidate cover.
- Some have conditions about preserving evidence, not paying a ransom without consent, or not admitting liability publicly.
Write the incident line number and policy number on your offline emergency contact sheet, so it is to hand when your systems are not.
What to do in the first hours
- Start your incident log immediately. Insurers expect a clear, timestamped record of what happened and what you did.
- Check your policy’s notification requirement and, if it applies, call the insurer’s incident line early, often before engaging anyone else.
- Follow their instructions on which responders to use.
- Preserve evidence rather than wiping or “cleaning” systems, because it supports both recovery and the claim.
- Do not open communication with an attacker, or make any payment, without your insurer’s involvement where the policy requires it.
- Avoid public statements that admit liability before you understand what happened.
What insurers expect you to have in place
Increasingly, insurers do not just pay out, they expect you to have basic controls in place as a condition of cover, and they may ask about them at claim time. Common expectations include multi-factor authentication on key accounts, tested backups, endpoint security, a patching process, and staff awareness. If you attested to having these when you took out the policy, make sure you actually do. A gap between what you declared and what you had can become a problem when you claim. Our cyber insurance readiness guide covers what insurers typically look for.
Keep the evidence a claim needs
A claim is supported by evidence: your incident log, what was affected, what it cost, and what you did to contain and recover. The free Cyber Incident Response Toolkit includes an incident log and evidence register that make this straightforward, and our guide to preserving evidence explains the basics. Good records help you recover faster and claim more smoothly.
Would your controls stand up at claim time?
We can review your security against what cyber insurers typically expect, close the gaps, and help you build the evidence and processes that make a claim go smoothly rather than becoming a second problem.
Frequently asked questions
Check your policy now, before you ever need it. Many cyber policies require you to notify their incident line early and to use their approved responders, and engaging your own help first can reduce or invalidate cover. Others are more flexible. Knowing your policy’s requirements in advance means you are not reading the small print during a crisis.
Common pitfalls include not notifying the insurer within the required time, engaging your own responders when the policy required theirs, paying a ransom without consent, admitting liability publicly, destroying evidence, or a gap between the controls you declared and the controls you actually had. Reading your policy in advance avoids most of these.
Increasingly they expect basic controls as a condition of cover, commonly multi-factor authentication on key accounts, tested backups, endpoint security, a patching process and staff awareness. If you attested to having these, make sure you genuinely do, because a gap can cause problems at claim time.
A clear, timestamped incident log, a record of what was affected and what it cost, and evidence of how you contained and recovered. Keeping an incident log and evidence register from the first hour, as in our free toolkit, supports both faster recovery and a smoother claim.
Related reading: the full Cyber Incident Response Plan guide, the Cyber Insurance Readiness Guide, and the free Cyber Incident Response Toolkit.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


