Cyber & Insurance Technology

Cyber Insurance Claims After an Incident: What to Do in the First 24 Hours

A practical cyber-claim response checklist covering insurer notice, evidence preservation, forensics, breach counsel, vendor approval, legal notification duties and cost documentation after an incident.

Two technology professionals examining computer screens in an office, illustrating coordinated cyber incident and insurance claim response
Photo: Mushvig Niftaliyev / Unsplash
Short answer: After a cyber incident, the first priority is to contain harm without destroying evidence, activate the organization’s incident-response team, and notify the cyber insurer or broker as quickly as the policy requires. Many cyber policies coordinate access to breach counsel, forensic investigators, notification vendors and other specialists, so incurring major outside costs before checking consent or panel requirements can complicate reimbursement.

A cyber insurance claim begins while the incident is still unfolding. Decisions made in the first hours can affect security, legal obligations and insurance recovery. The Federal Trade Commission (FTC) recommends moving quickly to secure systems, mobilize a breach-response team, preserve forensic evidence and determine notification requirements.

1. Contain the incident without destroying evidence

Disconnect or isolate affected systems when appropriate, but avoid wiping, reimaging or casually powering down devices that may contain evidence. The FTC specifically warns businesses not to destroy forensic evidence and recommends working with forensic specialists to determine the source and scope of the breach.

2. Notify the insurer or broker early

Read the policy’s notice condition and use the carrier’s incident hotline if one is provided. Cyber insurers often maintain response networks that can mobilize forensic specialists, breach counsel and crisis-communications resources. Coalition’s incident-response guidance, for example, advises policyholders to report incidents promptly so the necessary specialists can be activated.

Do not assume that every outside vendor will automatically be reimbursed. Some policies require prior consent, use of panel vendors or agreement on rates. If an emergency requires immediate action, document why the expense was necessary and notify the insurer as soon as possible.

3. Bring legal and forensic teams together

Cyber incidents can trigger privacy, contractual, sector-specific and state notification obligations. The FTC recommends consulting legal counsel and using qualified forensic investigators. Counsel can help coordinate legal analysis while forensic specialists preserve system images, logs and other evidence.

4. Build an incident timeline

Record Why it matters
Discovery time and alerts Establishes when the organization became aware of the event.
Affected systems and users Helps define scope and business interruption.
Containment steps Documents efforts to limit further damage.
Insurer/broker notices Supports compliance with policy notification requirements.
Vendor invoices and approvals Supports reimbursement of covered response costs.
Downtime and lost income records Can support a cyber business-interruption claim where covered.

5. Determine what data and systems were affected

Do not announce conclusions before the investigation supports them. The FTC recommends identifying the types of information involved, the number of people affected, whether unauthorized access occurred and what remediation is needed. This analysis can affect privacy notifications, regulatory reporting and third-party liability.

6. Coordinate law enforcement and notification duties

The FTC notes that every U.S. state, the District of Columbia, Puerto Rico and the U.S. Virgin Islands have breach-notification laws involving personal information, and additional federal or sector rules may apply. Timing and content requirements differ. Counsel should determine which rules apply to the specific data and organization.

For serious cybercrime, organizations may also contact appropriate law-enforcement agencies. Coordinate public statements and customer notices so they do not interfere with the investigation or create inaccurate claims.

7. Treat ransom decisions as a legal, security and insurance issue

Law enforcement does not recommend paying ransom, and payment does not guarantee recovery. If extortion is involved, involve counsel, the insurer, incident-response professionals and appropriate authorities before making decisions. Cyber policies can contain consent, sanctions, sublimit and vendor requirements that must be reviewed.

First-24-hours claim checklist

  • Activate the incident-response plan and executive contacts.
  • Isolate affected systems while preserving evidence.
  • Notify the cyber insurer/broker under the policy’s notice procedure.
  • Confirm approved counsel, forensics and other response vendors.
  • Preserve logs, emails, security alerts and system images.
  • Track every response expense and approval.
  • Identify affected data, systems, vendors and business processes.
  • Assess legal and regulatory notification duties.
  • Document downtime, extra expense and lost-income evidence.

Frequently asked questions

Should a company call the cyber insurer before hiring a forensic firm?

When practical, yes. Some policies have consent or panel-vendor requirements. In an emergency, take reasonable steps to limit harm but document the need and contact the insurer quickly.

Should infected computers be wiped immediately?

Not before preserving evidence. Forensic data can be critical to understanding scope, legal obligations and the insurance claim.

Does cyber insurance automatically pay every breach-response cost?

No. Coverage depends on the policy’s insuring agreements, exclusions, sublimits, retention, notice terms and vendor requirements.

Who decides whether customers must be notified?

Applicable law and the facts of the breach control. Privacy counsel should analyze state, federal, contractual and sector-specific duties.

Reviewed October 3, 2026. Cyber policy notice, consent, vendor and reimbursement requirements vary; the policy and applicable breach laws control.