Rakshit Financial ServicesInsurance broker · Udaipur

← rakshitinsurance.com

How to file a cyber insurance claim

2026-09-04 · Parul Bhargava

Written by Parul Bhargava · Founder and Principal Advisor, advising since 2004

How to file a cyber insurance claim

To file a cyber insurance claim, notify your insurer within the policy’s first‑notice window, usually 24 hours, by calling the dedicated hotline and emailing a concise incident summary with timestamps, screenshots and impact details. Attach the policy schedule, claim form, forensic report and any legal retainer documents before the deadline.

QUICK ANSWER

1. As soon as the breach is discovered, isolate the affected systems and preserve every log, screenshot and alert. Turn off network connections only after you have captured volatile data; do not delete emails, firewall logs or backup files. The moment you start cleaning without documentation, the insurer will argue that evidence is missing and may reduce the payout.

When ransomware freezes accounting systems

2. Within the first two hours, inform your internal incident response team and the designated cyber‑risk officer. Their written acknowledgment of the incident creates a paper trail that the insurer will expect. Simultaneously, call the insurer’s 24‑hour claim hotline, most policies require notice within a specified period, often 24 hours, and missing that window can trigger a denial. Record the claim reference number, the name of the claim handler and the exact time of the call.

3. After the initial call, send a formal written notice to the insurer’s claims department. Use the email address or portal specified in your policy schedule, and attach a concise incident summary: date and time of detection, nature of the attack (ransomware, data exfiltration, DDoS), systems impacted, and immediate containment steps taken. Keep a copy of this email and any delivery receipt; the insurer will check the timestamp against the policy’s notice clause.

The insurer’s 24‑hour cyber‑claims hotline

4. Gather the documentary pack the insurer will request. Typical items include: • The original policy schedule and any endorsements covering cyber risk. • A forensic report from a qualified investigator, signed and dated, detailing the attack vector, scope of data compromised and estimated financial loss.

• Screenshots of ransom notes, phishing emails, or error messages that triggered the alarm. • Copies of all relevant logs, server, IDS/IPS, VPN, email gateway, for the period covering at least 30 days before and after the breach. • Proof of third‑party expenses such as legal counsel, public relations firms, and credit monitoring services for affected customers.

Surveyor’s three‑point breach assessment criteria

• A detailed cost sheet of business interruption, including lost revenue, extra staffing and any regulatory fines already imposed. Do not submit drafts or unsigned reports; the insurer will reject anything that is not final and certified. 5. When the insurer assigns a surveyor, expect a site visit or a virtual walkthrough. The surveyor will verify that you have complied with the policy’s risk‑management obligations, for example, that you maintained up‑to‑date anti‑malware solutions, conducted regular vulnerability scans and had a documented incident‑response plan. They will also compare the forensic findings with your internal logs to ensure consistency. Any discrepancy, such as a missing patch that was required by the policy, can lead to a partial denial under the “failure to maintain required security controls” clause.

6. Avoid common pitfalls that shrink the settlement. First, never alter logs after the breach; tampering is a red flag and may be deemed fraud. Second, do not settle with the attacker before informing the insurer; many policies require that you seek insurer consent before paying ransom, and unilateral payment can void the claim. Third, keep personal devices out of the investigation, mixing personal and corporate data often triggers privacy objections and delays. Fourth, do not underestimate the importance of notifying the data‑protection authority within the statutory window; failure to do so can be cited as a breach of the policy’s regulatory‑compliance clause.

Requesting a detailed settlement statement

7. Once the surveyor submits their report, the insurer will issue a settlement offer. Review it against the cost sheet you prepared. If the amount appears low, check whether the insurer has applied the average clause for under‑insurance. Under the standard cyber wording, a shortfall of up to 15 percent of the insured sum is waived; beyond that, the claim is reduced proportionally. Verify the insured sum in your policy schedule and confirm that the loss calculation respects this threshold.

8. If you believe the offer is wrong, raise a formal objection in writing within the period stipulated in the policy, usually 15 days from receipt of the offer. Attach a point‑by‑point rebuttal, referencing the forensic report, the cost sheet and the specific policy wording that supports your position. Request a re‑assessment by a senior claims manager or, if needed, invoke the internal dispute‑resolution mechanism described in the policy schedule.

Keeping a dedicated claim folder

9. Should the insurer still refuse a fair settlement, you may approach the IRDAI grievance redressal portal, but only after exhausting the insurer’s internal process. Prepare a concise dossier containing the original claim notice, all correspondence, the surveyor’s report and the insurer’s justification for denial. The regulator will look for compliance with the policy’s notice period, documentation requirements and any breach of the insurer’s duty of good faith.

10. Throughout the process, keep a chronological log of every phone call, email and meeting, noting dates, times, participants and key decisions. This log becomes the backbone of any legal or regulatory challenge and demonstrates that you acted promptly and transparently. 11. After the claim is settled, conduct a post‑mortem and update your risk‑management framework. Document lessons learned, patch any identified vulnerabilities and, if the insurer’s underwriting questionnaire highlighted gaps, consider adjusting your coverage limits or adding endorsements. A stronger risk posture not only reduces future premiums but also positions you better for any subsequent claim.

12. Finally, retain all claim‑related documents for the period required by law and by your policy, typically three years. Should a future audit or dispute arise, you will have the complete paper trail ready, avoiding the need to recreate evidence under pressure. By following these steps methodically, you protect the value of your cyber cover, minimise the chance of a reduced payout and keep your business’s reputation intact during a crisis.

Common approaches to filing a cyber claim in India
ApproachKey BenefitTypical Cost
Self‑Managed ClaimFull control over documentation and timelineLow, only policy premium
Broker Assisted ClaimExpert guidance and faster document collationModerate, broker fee may apply
Third‑Party AdjusterIndependent assessment, reduces dispute riskHigher, adjuster fee plus possible extra charges

BROKER'S NOTE

In practice, insurers often scrutinise the chain of custody for digital evidence. If you alter logs or fail to preserve original files, the adjuster may claim tampering and reduce the payout. Maintaining a read‑only copy of all logs and handing over only the forensic‑verified version protects the claim’s integrity.

Frequently asked questions

How quickly should I inform my insurer after a cyber breach?

You should call the insurer’s 24‑hour cyber‑claims hotline and send an email within 24 hours of confirming the breach. This satisfies the first‑notice requirement and prevents the insurer from invoking the average clause or claiming delayed mitigation.

What documents are essential for a cyber claim in India?

Key documents include the policy schedule, signed claim form, detailed incident log with timestamps, forensic analysis report, network logs, screenshots of errors, and any legal retainer agreements. Third‑party cooperation letters also strengthen your case.

Can I submit a claim without a forensic report?

While you can start the claim without a forensic report, insurers typically request a professional analysis before processing payment. Submitting a report later may delay settlement and could affect the payout amount.

क्या मुझे अपने IT टीम को भी क्लेम में शामिल करना चाहिए?

हां, IT टीम के विस्तृत इन्सिडेंट लॉग, स्क्रीनशॉट और टाइमस्टैम्प क्लेम फाइल में जरूरी होते हैं। उनका लिखित प्रमाण बीमा कंपनी को आपके त्वरित कार्य को दिखाता है और कम भुगतान के दावे को रोकता है।

What happens if I miss the first‑notice window?

Missing the 24‑hour notice can allow the insurer to invoke the average clause, argue insufficient mitigation, and potentially reduce the settlement. In some cases, they may deny the claim entirely, making prompt reporting critical.

Get a free written policy review at rakshitinsurance.com/#policy-review or WhatsApp +91 92514 56334.

READ NEXT

FOLLOW THE DESK

Rakshit Financial Services is an IRDAI-registered insurance broker with offices in Udaipur, Jaipur and Mumbai. This article is general information only and is not insurance advice or a solicitation to purchase. Insurance is the subject matter of solicitation. Please read the policy wording, benefits, exclusions and terms carefully before concluding a sale. Cover and eligibility are subject to insurer underwriting.

SHARE THIS NOTE

WhatsApp · LinkedIn · X · Copy link

RELATED COVER

Business Interruption Insurance in India · Cyber Insurance in India: What It Actually Pays · Fidelity Guarantee: Cover Against Employee Dishonesty · Fire & Burglary Insurance for Indian Factories

MORE FROM THE DESK

Factory insurance for engineering units in Bhiwadi
How claims history changes your renewal premium
Machinery breakdown claim steps you must follow within the first 24 hours