Had a loss? Call the deskCall the desk92514 56334WhatsAppSign in to your claimSign inClaims across India

Cyber and Data

Ransomware, intrusion, data breach and the cost of responding to them: investigation, restoration, notification, liability and business interruption.

Also calledCyber Liability · Cyber Risk · Data Protection

File/Claims library/Liability/Cyber and data

First thing, todayIsolate without wiping, and read the incident-response clause before you call anybody. Most policies pay only for their own panel.

Three deadlines
  • Tell the insurer now, not after the assessment.
  • Keep the logs and report it wherever the rules require, before anything is rebuilt.
  • Every document within the time the insurer asks for it.
A server rack with a cable pulled and cut
A server rack with a cable pulled and cut. An illustration.

When you would claim

  • Ransomware or a systems intrusion
  • Business email compromise and funds transferred
  • Data breach affecting customers or employees
  • Systems down and revenue lost while they are restored

What insurers most often rely on

  • Responders engaged outside the insurer's panel
  • A ransom paid or negotiated without written consent
  • Systems rebuilt before imaging, so the cause cannot be established
  • Known unpatched vulnerabilities, where the wording requires a minimum standard
  • Notification outside the short window these policies specify

On a liability claim these are opening positions. Opening positions are argued, and the insurer expects them to be.

The documents

half of it belongs to the other side

10 items, and half of them are somebody else's. Get the allegation in writing early: an insurer cannot tell you what is covered until it can read what is being said against you.

  • Claim form and the incident timeline, hour by hour
  • Forensic report from the insurer's appointed responder
  • System, firewall, VPN and email gateway logs from before the incident
  • Regulatory notifications made, and the correspondence
  • Evidence of the funds transferred and the bank's response
  • Invoices separated by head: investigation, restoration, legal and notification
  • Records of systems down and output lost, from the first hour
  • Details of any other insurance covering the same risk
  • A claim bill: the amount claimed, itemised, with the working behind it
  • Cancelled cheque and bank details in the insured's name, for the NEFT payment
Every letter, datedA liability file is a correspondence file. Log the date each notice arrived, the date you passed it on, and the date the insurer replied. Delay is the first thing argued and the easiest to answer.

Next

Cyber Incident Claim: The First Hours

Cyber policies are unusual: most of them tell you who to call, and calling somebody else first can cost you the cover.

Most often lost by: Wiping and rebuilding before anyone images the systems -- and engaging your own IT firm or paying a ransom before the insurer approves it.

Read the limit of indemnity

No sum insured and no average clause. A liability policy is capped by its limit of indemnity, written as one figure for any one accident and a larger one for the year, with defence costs sometimes inside that limit and sometimes outside it. Which of the two it is matters more than the figure.

Filed under: Liability · Cyber and data

Claims that sit next to this one

the same allegation, answered elsewhere

Directors' and Officers' Liability

the board's answer for a breach

Professional Indemnity

a client's loss caused by yours

Electronic Equipment

the hardware, where that is what broke

Systems down and unsure who you are allowed to call? Report a loss or call 92514 56334.