Cyber Claims Process
How a cyber claim runs from discovery to settlement: notifying the insurer, incident response and forensics, preserving evidence, regulatory reporting, the business interruption waiting period, and subrogation.
A claim that starts while the loss is still happening
Unlike many claims, a cyber breach is often still unfolding when the claim begins: it is an ongoing event, and delay increases the damage. The claims process therefore involves immediate incident response, forensic investigation, regulatory notification, loss quantification and settlement, with the first of these measured in hours.
First steps
The first step on discovering a breach is to notify the insurer and activate the incident response plan. An Incident Response Plan (IRP) is the document a business keeps ready before any incident. It sets out who to contact, how to contain the breach, the communication protocols and the escalation procedures. Having one reduces response time and claim disputes.
Three instinctive reactions are wrong. Reformatting or wiping the compromised systems destroys digital forensic evidence, such as logs, malware artefacts and attack traces, that is essential for the investigation, for regulatory reporting and for substantiating the claim. Announcing the breach on social media comes only after proper assessment. Waiting weeks before telling anyone breaches CERT-In's requirement that covered entities report listed incidents within 6 hours of noticing them or being told of them.
The forensic investigator
The forensic investigator's job is to identify how the breach occurred (the attack vector), contain the ongoing damage, assess the scope of the compromised data, preserve evidence for legal proceedings and recommend remediation measures. The cost of this work is a first-party cover under the policy.
The investigator's findings feed every later stage. They show what has to be reported to regulators, which people have to be notified, and whether any policy condition or exclusion is in play.
Quantifying the loss, and recovery afterwards
Business interruption cover in a cyber policy commonly carries a waiting period expressed in hours. Cover begins only after that period has passed, so the first hours of downtime are borne by the insured. The length of the waiting period is set by each policy.
After paying the claim, the insurer may pursue recovery from a third party whose negligence caused the breach, for example a vendor with poor security. This is subrogation. The insured must cooperate with the insurer's subrogation efforts.
Rules at a glance
The first evening of a ransomware attack
Illustration: at 6 pm the IT head of a logistics firm in Pune finds the servers encrypted and a ransom note on screen. Following the firm's incident response plan, she informs the insurer, isolates the affected machines from the network without wiping them, and calls in the forensic investigators. The listed incident is reported to CERT-In within 6 hours of its being noticed. A colleague's suggestion to reformat everything and restore from back-up at once is set aside until the investigators have preserved the logs and the malware samples. Public statements wait until the scope is known.
Business interruption after a waiting period
- Assumptions, for arithmetic only: the policy has an 8-hour waiting period for business interruption; a ransomware attack causes 72 hours of downtime; the insured loss of income is taken at a flat ₹50,000 per hour.
- Hours covered = 72 − 8 = 64 hours.
- Covered business interruption loss = 64 × ₹50,000 = ₹32,00,000, before any other term of the policy.
- Loss during the waiting period, borne by the insured = 8 × ₹50,000 = ₹4,00,000.
- Check: ₹32,00,000 + ₹4,00,000 = ₹36,00,000 = 72 × ₹50,000.
Result. Of 72 hours of downtime, 64 hours are covered. On the assumed figures that is ₹32,00,000 of a ₹36,00,000 loss, with ₹4,00,000 falling in the waiting period.
Key points
- The first step after discovering a breach is to notify the insurer and activate the incident response plan.
- Compromised systems are not reformatted at once, because that destroys the forensic evidence needed for investigation, reporting and the claim.
- Covered entities must report listed incidents to CERT-In within 6 hours of noticing them or being told of them.
- The forensic investigator identifies the attack vector, contains the breach, assesses its scope and preserves evidence.
- Business interruption loss is covered only after the policy's waiting period.
- After paying, the insurer can recover from a responsible third party by subrogation, and the insured must cooperate.
Common misunderstandings
- Wiping the systems is not the fastest route to recovery of the claim: it destroys the evidence the claim depends on.
- The waiting period is not a delay in payment: it is the initial stretch of downtime for which no business interruption loss is covered.
- Notifying the insurer does not replace regulatory reporting: CERT-In's 6-hour requirement applies separately to covered entities.
- Subrogation rights pass to the insurer on payment as the policy provides, and the insured must cooperate with recovery efforts.
Questions people ask
What does an incident response plan contain?
Who to contact, how to contain the breach, the communication protocols and the escalation procedures to follow during a cyber incident.
Why does the insurer want to be told at the very start?
A breach is an ongoing event and delay increases the damage. Early notice lets the response, the forensic work and the preservation of evidence begin while they can still limit the loss.
Who can the insurer recover from after paying a cyber claim?
A third party whose negligence caused the breach, such as a vendor with poor security.
What this lesson relies on
- Cyber insurance policy wording — notification, incident response, business interruption waiting period, subrogation
- CERT-In Directions of 28 April 2022
This lesson was reviewed independently against these sources on 8 October 2026. Rules change: check the current regulation, scheme document or policy wording before relying on any figure. This is education, not advice.

