Cyber Insurance and Incident Response: What to Do Before You Claim - System Force IT

Cyber Insurance and Incident Response: What to Do Before You Claim

Cyber insurance can be the difference between a bad week and a business-ending event. But a policy only pays out if you use it correctly, and the mistakes that reduce or void a claim are almost always made in the first few hours of an incident, by people acting fast and in good faith. Knowing your policy before you need it is one of the cheapest forms of protection there is.

This guide explains what to do, and what to avoid, so that your cyber insurance actually helps when the time comes. It is a companion to our full cyber incident response plan guide and pairs with our cyber insurance readiness guide.

Read your policy before there is an incident

The single most useful thing you can do is understand your policy while everything is calm. Cyber policies vary enormously, and several common terms directly affect how you should respond:

  • Many policies require you to notify their incident line early, sometimes within a set number of hours of becoming aware.
  • Many require you to use their approved responders (an incident-response panel), and engaging your own help first can reduce or invalidate cover.
  • Some have conditions about preserving evidence, not paying a ransom without consent, or not admitting liability publicly.

Write the incident line number and policy number on your offline emergency contact sheet, so it is to hand when your systems are not.

The most common and costly mistake is engaging your own IT or forensic help, or starting recovery, before calling the insurer, when the policy required them to be involved from the start. Well-intentioned fast action can quietly reduce a payout. When in doubt, check your policy’s requirements before you act.

What to do in the first hours

  • Start your incident log immediately. Insurers expect a clear, timestamped record of what happened and what you did.
  • Check your policy’s notification requirement and, if it applies, call the insurer’s incident line early, often before engaging anyone else.
  • Follow their instructions on which responders to use.
  • Preserve evidence rather than wiping or “cleaning” systems, because it supports both recovery and the claim.
  • Do not open communication with an attacker, or make any payment, without your insurer’s involvement where the policy requires it.
  • Avoid public statements that admit liability before you understand what happened.

What insurers expect you to have in place

Increasingly, insurers do not just pay out, they expect you to have basic controls in place as a condition of cover, and they may ask about them at claim time. Common expectations include multi-factor authentication on key accounts, tested backups, endpoint security, a patching process, and staff awareness. If you attested to having these when you took out the policy, make sure you actually do. A gap between what you declared and what you had can become a problem when you claim. Our cyber insurance readiness guide covers what insurers typically look for.

Keep the evidence a claim needs

A claim is supported by evidence: your incident log, what was affected, what it cost, and what you did to contain and recover. The free Cyber Incident Response Toolkit includes an incident log and evidence register that make this straightforward, and our guide to preserving evidence explains the basics. Good records help you recover faster and claim more smoothly.

Would your controls stand up at claim time?

We can review your security against what cyber insurers typically expect, close the gaps, and help you build the evidence and processes that make a claim go smoothly rather than becoming a second problem.

Book a free IT and security review

Frequently asked questions

Should I contact my cyber insurer before taking action?

Check your policy now, before you ever need it. Many cyber policies require you to notify their incident line early and to use their approved responders, and engaging your own help first can reduce or invalidate cover. Others are more flexible. Knowing your policy’s requirements in advance means you are not reading the small print during a crisis.

What can void or reduce a cyber insurance claim?

Common pitfalls include not notifying the insurer within the required time, engaging your own responders when the policy required theirs, paying a ransom without consent, admitting liability publicly, destroying evidence, or a gap between the controls you declared and the controls you actually had. Reading your policy in advance avoids most of these.

What do insurers expect us to have in place?

Increasingly they expect basic controls as a condition of cover, commonly multi-factor authentication on key accounts, tested backups, endpoint security, a patching process and staff awareness. If you attested to having these, make sure you genuinely do, because a gap can cause problems at claim time.

What evidence does a cyber insurance claim need?

A clear, timestamped incident log, a record of what was affected and what it cost, and evidence of how you contained and recovered. Keeping an incident log and evidence register from the first hour, as in our free toolkit, supports both faster recovery and a smoother claim.

Related reading: the full Cyber Incident Response Plan guide, the Cyber Insurance Readiness Guide, and the free Cyber Incident Response Toolkit.

Practical guidance, not legal or insurance advice. Check your own policy terms and take professional advice for your circumstances. From System Force IT, UKAS ISO/IEC 27001:2022 certified, supporting UK businesses since 2006.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name