
To file a cyber insurance claim, notify your insurer within the policy’s first‑notice window, usually 24 hours, by calling the dedicated hotline and emailing a concise incident summary with timestamps, screenshots and impact details. Attach the policy schedule, claim form, forensic report and any legal retainer documents before the deadline.
1. As soon as the breach is discovered, isolate the affected systems and preserve every log, screenshot and alert. Turn off network connections only after you have captured volatile data; do not delete emails, firewall logs or backup files. The moment you start cleaning without documentation, the insurer will argue that evidence is missing and may reduce the payout.
2. Within the first two hours, inform your internal incident response team and the designated cyber‑risk officer. Their written acknowledgment of the incident creates a paper trail that the insurer will expect. Simultaneously, call the insurer’s 24‑hour claim hotline, most policies require notice within a specified period, often 24 hours, and missing that window can trigger a denial. Record the claim reference number, the name of the claim handler and the exact time of the call.
3. After the initial call, send a formal written notice to the insurer’s claims department. Use the email address or portal specified in your policy schedule, and attach a concise incident summary: date and time of detection, nature of the attack (ransomware, data exfiltration, DDoS), systems impacted, and immediate containment steps taken. Keep a copy of this email and any delivery receipt; the insurer will check the timestamp against the policy’s notice clause.
4. Gather the documentary pack the insurer will request. Typical items include: • The original policy schedule and any endorsements covering cyber risk. • A forensic report from a qualified investigator, signed and dated, detailing the attack vector, scope of data compromised and estimated financial loss.
• Screenshots of ransom notes, phishing emails, or error messages that triggered the alarm. • Copies of all relevant logs, server, IDS/IPS, VPN, email gateway, for the period covering at least 30 days before and after the breach. • Proof of third‑party expenses such as legal counsel, public relations firms, and credit monitoring services for affected customers.
• A detailed cost sheet of business interruption, including lost revenue, extra staffing and any regulatory fines already imposed. Do not submit drafts or unsigned reports; the insurer will reject anything that is not final and certified. 5. When the insurer assigns a surveyor, expect a site visit or a virtual walkthrough. The surveyor will verify that you have complied with the policy’s risk‑management obligations, for example, that you maintained up‑to‑date anti‑malware solutions, conducted regular vulnerability scans and had a documented incident‑response plan. They will also compare the forensic findings with your internal logs to ensure consistency. Any discrepancy, such as a missing patch that was required by the policy, can lead to a partial denial under the “failure to maintain required security controls” clause.
6. Avoid common pitfalls that shrink the settlement. First, never alter logs after the breach; tampering is a red flag and may be deemed fraud. Second, do not settle with the attacker before informing the insurer; many policies require that you seek insurer consent before paying ransom, and unilateral payment can void the claim. Third, keep personal devices out of the investigation, mixing personal and corporate data often triggers privacy objections and delays. Fourth, do not underestimate the importance of notifying the data‑protection authority within the statutory window; failure to do so can be cited as a breach of the policy’s regulatory‑compliance clause.
7. Once the surveyor submits their report, the insurer will issue a settlement offer. Review it against the cost sheet you prepared. If the amount appears low, check whether the insurer has applied the average clause for under‑insurance. Under the standard cyber wording, a shortfall of up to 15 percent of the insured sum is waived; beyond that, the claim is reduced proportionally. Verify the insured sum in your policy schedule and confirm that the loss calculation respects this threshold.
8. If you believe the offer is wrong, raise a formal objection in writing within the period stipulated in the policy, usually 15 days from receipt of the offer. Attach a point‑by‑point rebuttal, referencing the forensic report, the cost sheet and the specific policy wording that supports your position. Request a re‑assessment by a senior claims manager or, if needed, invoke the internal dispute‑resolution mechanism described in the policy schedule.
9. Should the insurer still refuse a fair settlement, you may approach the IRDAI grievance redressal portal, but only after exhausting the insurer’s internal process. Prepare a concise dossier containing the original claim notice, all correspondence, the surveyor’s report and the insurer’s justification for denial. The regulator will look for compliance with the policy’s notice period, documentation requirements and any breach of the insurer’s duty of good faith.
10. Throughout the process, keep a chronological log of every phone call, email and meeting, noting dates, times, participants and key decisions. This log becomes the backbone of any legal or regulatory challenge and demonstrates that you acted promptly and transparently. 11. After the claim is settled, conduct a post‑mortem and update your risk‑management framework. Document lessons learned, patch any identified vulnerabilities and, if the insurer’s underwriting questionnaire highlighted gaps, consider adjusting your coverage limits or adding endorsements. A stronger risk posture not only reduces future premiums but also positions you better for any subsequent claim.
12. Finally, retain all claim‑related documents for the period required by law and by your policy, typically three years. Should a future audit or dispute arise, you will have the complete paper trail ready, avoiding the need to recreate evidence under pressure. By following these steps methodically, you protect the value of your cyber cover, minimise the chance of a reduced payout and keep your business’s reputation intact during a crisis.
| Approach | Key Benefit | Typical Cost |
|---|---|---|
| Self‑Managed Claim | Full control over documentation and timeline | Low, only policy premium |
| Broker Assisted Claim | Expert guidance and faster document collation | Moderate, broker fee may apply |
| Third‑Party Adjuster | Independent assessment, reduces dispute risk | Higher, adjuster fee plus possible extra charges |
In practice, insurers often scrutinise the chain of custody for digital evidence. If you alter logs or fail to preserve original files, the adjuster may claim tampering and reduce the payout. Maintaining a read‑only copy of all logs and handing over only the forensic‑verified version protects the claim’s integrity.
You should call the insurer’s 24‑hour cyber‑claims hotline and send an email within 24 hours of confirming the breach. This satisfies the first‑notice requirement and prevents the insurer from invoking the average clause or claiming delayed mitigation.
Key documents include the policy schedule, signed claim form, detailed incident log with timestamps, forensic analysis report, network logs, screenshots of errors, and any legal retainer agreements. Third‑party cooperation letters also strengthen your case.
While you can start the claim without a forensic report, insurers typically request a professional analysis before processing payment. Submitting a report later may delay settlement and could affect the payout amount.
हां, IT टीम के विस्तृत इन्सिडेंट लॉग, स्क्रीनशॉट और टाइमस्टैम्प क्लेम फाइल में जरूरी होते हैं। उनका लिखित प्रमाण बीमा कंपनी को आपके त्वरित कार्य को दिखाता है और कम भुगतान के दावे को रोकता है।
Missing the 24‑hour notice can allow the insurer to invoke the average clause, argue insufficient mitigation, and potentially reduce the settlement. In some cases, they may deny the claim entirely, making prompt reporting critical.
Get a free written policy review at rakshitinsurance.com/#policy-review or WhatsApp +91 92514 56334.
Cyber insurance · Free policy review · All insurance calculators
Rakshit Financial Services is an IRDAI-registered insurance broker with offices in Udaipur, Jaipur and Mumbai. This article is general information only and is not insurance advice or a solicitation to purchase. Insurance is the subject matter of solicitation. Please read the policy wording, benefits, exclusions and terms carefully before concluding a sale. Cover and eligibility are subject to insurer underwriting.
WhatsApp · LinkedIn · X · Copy link
Business Interruption Insurance in India · Cyber Insurance in India: What It Actually Pays · Fidelity Guarantee: Cover Against Employee Dishonesty · Fire & Burglary Insurance for Indian Factories
Factory insurance for engineering units in Bhiwadi
How claims history changes your renewal premium
Machinery breakdown claim steps you must follow within the first 24 hours