Contain it without destroying the evidence, and read the policy before you call anyone.
Cyber policies are unusual: most of them tell you who to call, and calling somebody else first can cost you the cover.
What loses itWiping and rebuilding before anyone images the systems -- and engaging your own IT firm or paying a ransom before the insurer approves it. Most cyber policies only pay for responders drawn from their own panel.
- Isolate, but do not wipeDisconnect affected systems from the network and leave them powered in whatever state they are in where you safely can. Volatile memory and logs are the forensic evidence, and a rebuild destroys them.Immediately
- Read the incident-response clause before you call your IT firmMost cyber policies require you to use responders from the insurer's panel and will not pay for anyone else. This is the single most expensive difference between cyber and every other class.Before engaging anyone
- Notify the insurer on the incident hotlineCyber wordings usually carry a dedicated notification route with a short window attached. Use that route rather than a general claims email.Immediately
- Check your regulatory reporting obligationsCERT-In's directions require certain classes of cyber incident to be reported within a short, specific window, and sector regulators impose their own. Confirm what applies to you today rather than relying on memory -- these have changed more than once.Check at once
- Preserve logs before retention expiresFirewall, VPN, endpoint, email gateway, domain controller, backup server. Many roll over within days, and the logs from the week before the incident are usually the ones that matter.Day 1
- Do not pay, negotiate or communicate with the attackerNot without the insurer's written agreement. Payment can breach the policy, and in some circumstances it raises legal exposure of its own.Never unilaterally
- Record the business interruption from the first hourSystems down, orders unprocessed, staff idle, workarounds paid for. Cyber business interruption is measured in hours and the record has to start with the incident.From hour 1
- Keep the forensic report and the remediation invoices separateInvestigation, restoration, ransom, legal, notification and lost income usually sit under different sub-limits. A single mixed invoice is very hard to allocate afterwards.Throughout
The quiet oneUnderinsurance. If the sum insured is below the value actually at risk, the average clause reduces the claim in proportion however well the rest of it is run. Check where you stand. It takes three numbers and nothing is stored.
Fire Claim
A fire, explosion, lightning strike or impact loss at a business premises.
Marine Cargo Claim
Goods damaged, short-landed or lost in transit by road, rail, sea or air.
Mid-incident? Call before your IT firm touches anything else.
Whoever placed your policy, and whatever stage the claim has reached.
Three deadlines
- Tell the insurer now, not after the assessment.
- Notice to anybody else responsible the carrier, the contractor, the police, within the time your policy sets.
- Every document within the time the insurer asks for it.