Had a loss? Call the deskCall the desk92514 56334WhatsAppSign in to your claimSign inClaims across India

Contain it without destroying the evidence, and read the policy before you call anyone.

Cyber policies are unusual: most of them tell you who to call, and calling somebody else first can cost you the cover.

Playbook/First 72 hours/Cyber Incident Claim
What loses itWiping and rebuilding before anyone images the systems -- and engaging your own IT firm or paying a ransom before the insurer approves it. Most cyber policies only pay for responders drawn from their own panel.
A server rack with a cable pulled and cut
A server rack with a cable pulled and cut.
1IMMEDIATELY2BEFORE ENGAGING ANYONE3IMMEDIATELY4CHECK AT ONCE5DAY 16NEVER UNILATERALLY7FROM HOUR 18THROUGHOUT
Red is the same day. The order is the whole point.
  1. Isolate, but do not wipeDisconnect affected systems from the network and leave them powered in whatever state they are in where you safely can. Volatile memory and logs are the forensic evidence, and a rebuild destroys them.Immediately
  2. Read the incident-response clause before you call your IT firmMost cyber policies require you to use responders from the insurer's panel and will not pay for anyone else. This is the single most expensive difference between cyber and every other class.Before engaging anyone
  3. Notify the insurer on the incident hotlineCyber wordings usually carry a dedicated notification route with a short window attached. Use that route rather than a general claims email.Immediately
  4. Check your regulatory reporting obligationsCERT-In's directions require certain classes of cyber incident to be reported within a short, specific window, and sector regulators impose their own. Confirm what applies to you today rather than relying on memory -- these have changed more than once.Check at once
  5. Preserve logs before retention expiresFirewall, VPN, endpoint, email gateway, domain controller, backup server. Many roll over within days, and the logs from the week before the incident are usually the ones that matter.Day 1
  6. Do not pay, negotiate or communicate with the attackerNot without the insurer's written agreement. Payment can breach the policy, and in some circumstances it raises legal exposure of its own.Never unilaterally
  7. Record the business interruption from the first hourSystems down, orders unprocessed, staff idle, workarounds paid for. Cyber business interruption is measured in hours and the record has to start with the incident.From hour 1
  8. Keep the forensic report and the remediation invoices separateInvestigation, restoration, ransom, legal, notification and lost income usually sit under different sub-limits. A single mixed invoice is very hard to allocate afterwards.Throughout
The quiet oneUnderinsurance. If the sum insured is below the value actually at risk, the average clause reduces the claim in proportion however well the rest of it is run. Check where you stand. It takes three numbers and nothing is stored.

Fire Claim

A fire, explosion, lightning strike or impact loss at a business premises.

Marine Cargo Claim

Goods damaged, short-landed or lost in transit by road, rail, sea or air.

Mid-incident? Call before your IT firm touches anything else.

Whoever placed your policy, and whatever stage the claim has reached.

Report a loss   Call 92514 56334

Three deadlines
  • Tell the insurer now, not after the assessment.
  • Notice to anybody else responsible the carrier, the contractor, the police, within the time your policy sets.
  • Every document within the time the insurer asks for it.