Chapter 28

Cyber Insurance and the IR Process

How cyber insurance intersects with incident response — when to notify the insurer, what coverage typically includes, the carrier-approved vendor requirement, and how IR decisions during the incident affect coverage.

Scenario

Day 2 of a ransomware incident. The CFO asks: "Are we covered for this?" Your cyber insurance policy is somewhere in the risk management team's shared drive. You've already: engaged an external IR firm, decided not to pay the ransom, and made several containment decisions that affected business continuity. The insurer wasn't notified until Day 2. The policy requires notification "as soon as practicable" and use of carrier-approved vendors for forensic investigation. You may have just voided coverage for the investigation costs. This chapter explains how to run the incident response and the insurance claim in parallel from T+0.

Before the Incident: Know Your Policy

The time to read your cyber insurance policy is not during an active incident. These are the critical policy terms to understand in advance.

Policy termWhat to look forWhy it matters during IR
Notification requirement"As soon as practicable" vs specific hours/daysMissing the notification window may void coverage — call the insurer at P1 declaration
Approved vendor panelList of pre-approved IR firms, forensic investigators, legal counselUsing a non-approved vendor may mean costs are not reimbursable — check before engaging external IR
Ransomware coverageDoes the policy cover ransom payment? Negotiation services? Decryptor reliability verification?Some policies require insurer pre-authorization before paying ransom
Business interruption coverageWaiting period (deductible in hours), period of restoration, covered vs excluded perilsThe clock for BI coverage usually starts after a "waiting period" — know the threshold
War / nation-state exclusionSome policies exclude "acts of war" — some carriers have applied this to nation-state cyberattacksIf the incident is attributed to a nation-state actor, coverage may be at risk
Prior acts exclusionSome policies exclude incidents that began before the policy inception dateFor long-dwell incidents, the initial access date may predate the policy — know your coverage window

T+0: Notify the Insurer Immediately

Most cyber policies have a notification hotline. Call it at the same time you call the external IR retainer — not after you've scoped the incident, not after you've contained it.

  Cyber Insurance Notification Flow
  ═══════════════════════════════════════════════════════════════════

  T+0 to T+2 hours:
    ├── Call insurance broker or carrier hotline
    ├── Open a claim / incident record number
    ├── Ask: Which IR firms are on your approved panel?
    ├── Ask: Is ransom payment pre-authorized up to what limit?
    └── Ask: What documentation do you need from us?

  Do NOT:
    ├── Engage non-panel IR firm without checking first
    ├── Make ransom payment decisions without insurer coordination
    ├── Make public statements about the incident without insurance/legal sign-off
    └── Wait to notify until after you've "confirmed" the scope
        (You don't need confirmed scope to open a claim)

  Insurer will typically:
    ├── Assign a claims handler as your point of contact
    ├── Connect you with their panel IR firm if you don't have a retainer
    ├── Begin tracking documented costs for reimbursement
    └── Coordinate ransom negotiation (if covered) through their vendors

What Cyber Insurance Typically Covers

Cost categoryTypically coveredCommon conditions
Forensic investigation costs (IR firm fees)Yes — if panel vendor used or non-panel pre-approvedMust use approved vendor list or get prior approval
Legal counsel (breach response)Yes — if panel legal firm usedMust use panel counsel for covered costs; you can use your own counsel in parallel at your own cost
Notification and credit monitoring costsYes — standard first-party coverageSubject to per-incident limits
Business interruption / lost revenueYes — subject to waiting period and restoration periodTypically 8-24 hour waiting period; must document revenue impact with financial records
Ransom paymentOften yes — with conditionsPre-authorization often required; OFAC sanctions check required (attacker on SDN list = payment illegal)
Extortion / "double extortion" data leakSome policies cover negotiation to prevent publicationPolicy language varies widely — check your specific policy
Regulatory fines (GDPR, HIPAA)Sometimes — insurable in some jurisdictionsNot insurable in all jurisdictions (EU GDPR fines intentionally designed as non-insurable penalties)
Common mistake: engaging non-panel IR vendors before checking with the insurer

Many organizations have both a cyber insurance policy and an existing IR retainer with a firm they've used for years. If the IR retainer firm is not on the insurer's approved vendor panel, the investigation costs may not be reimbursed — sometimes a $500,000+ gap. The insurer's approved panel exists because they've negotiated rates and quality standards with those firms. The fix is to resolve this before an incident: either ensure your preferred IR firm is added to your insurer's panel, or accept that you'll use the panel vendor for covered work and your preferred firm at your own cost. Never wait until an active P1 incident to discover this conflict.

Q & A

Q: The insurer's approved IR firm is less experienced with your specific environment than your existing retainer firm. Can you use both?

Yes — common practice is to use the insurer's panel firm for covered forensic investigation work (because the costs are reimbursable) and your existing retainer firm for operational IR support where you need their specific expertise. This requires coordination so the two firms don't duplicate work or conflict. Have outside counsel coordinate between the two — often the panel firm focuses on the forensic investigation report for legal and regulatory purposes, while your existing retainer handles the technical containment and recovery work. Document the split clearly so the insurer understands what work each firm performed and can reimburse appropriately.

Q: The attacker's identity is later determined to be a group with OFAC sanctions. You've already paid the ransom. What happens?

OFAC sanctions violations are strict liability — the fact that you didn't know the group was sanctioned at the time of payment is a mitigating factor but not a complete defense. OFAC guidance distinguishes between "voluntary self-disclosure" (which significantly reduces penalties) and discovered violations. If you paid the ransom and the group is later confirmed to be sanctioned: (1) Contact outside counsel and OFAC-specialized attorneys immediately. (2) Make a voluntary self-disclosure to OFAC — this is strongly advisable and dramatically reduces penalty exposure. (3) Preserve all documentation of the payment decision, the information available at the time, and any due diligence steps taken (like checking OFAC SDN list before payment). (4) Cyber insurance may not cover the OFAC fine — most policies specifically exclude penalties for sanctions violations. The lesson: check the OFAC SDN list before paying any ransom, not after.