Cyber and Data
Ransomware, intrusion, data breach and the cost of responding to them: investigation, restoration, notification, liability and business interruption.
Also calledCyber Liability · Cyber Risk · Data Protection
First thing, todayIsolate without wiping, and read the incident-response clause before you call anybody. Most policies pay only for their own panel.
- Tell the insurer now, not after the assessment.
- Keep the logs and report it wherever the rules require, before anything is rebuilt.
- Every document within the time the insurer asks for it.
When you would claim
- Ransomware or a systems intrusion
- Business email compromise and funds transferred
- Data breach affecting customers or employees
- Systems down and revenue lost while they are restored
What insurers most often rely on
- Responders engaged outside the insurer's panel
- A ransom paid or negotiated without written consent
- Systems rebuilt before imaging, so the cause cannot be established
- Known unpatched vulnerabilities, where the wording requires a minimum standard
- Notification outside the short window these policies specify
On a liability claim these are opening positions. Opening positions are argued, and the insurer expects them to be.
The documents
half of it belongs to the other side10 items, and half of them are somebody else's. Get the allegation in writing early: an insurer cannot tell you what is covered until it can read what is being said against you.
- Claim form and the incident timeline, hour by hour
- Forensic report from the insurer's appointed responder
- System, firewall, VPN and email gateway logs from before the incident
- Regulatory notifications made, and the correspondence
- Evidence of the funds transferred and the bank's response
- Invoices separated by head: investigation, restoration, legal and notification
- Records of systems down and output lost, from the first hour
- Details of any other insurance covering the same risk
- A claim bill: the amount claimed, itemised, with the working behind it
- Cancelled cheque and bank details in the insured's name, for the NEFT payment
Next
Cyber Incident Claim: The First Hours
Cyber policies are unusual: most of them tell you who to call, and calling somebody else first can cost you the cover.
Most often lost by: Wiping and rebuilding before anyone images the systems -- and engaging your own IT firm or paying a ransom before the insurer approves it.
Read the limit of indemnity
No sum insured and no average clause. A liability policy is capped by its limit of indemnity, written as one figure for any one accident and a larger one for the year, with defence costs sometimes inside that limit and sometimes outside it. Which of the two it is matters more than the figure.
Filed under: Liability · Cyber and data
Claims that sit next to this one
the same allegation, answered elsewhereDirectors' and Officers' Liability
the board's answer for a breach
Professional Indemnity
a client's loss caused by yours
Electronic Equipment
the hardware, where that is what broke
Systems down and unsure who you are allowed to call? Report a loss or call 92514 56334.