The moment a business discovers it has experienced a cyber incident — whether a data breach, ransomware attack, or system intrusion — a clock starts running. The decisions made in the first hours and days shape everything that follows: the scope of the damage, the legal obligations that must be met, and whether the insurance claim will ultimately be paid. Most business owners have never filed a cyber claim before and have no frame of reference for what the process looks like, who the players are, or what is expected of them. That uncertainty, combined with the pressure and chaos that accompany an active incident, leads to mistakes that are entirely preventable.

Cyber insurance is not like filing a claim after a car accident or a burst pipe. The policies are more complex, the coverage questions are more layered, and the process involves a web of professionals — forensic investigators, breach counsel attorneys, public relations specialists, notification vendors — all working simultaneously under the insurer’s oversight. The insured business sits at the center of this process and must make consequential decisions quickly, often without complete information.

This page walks through what actually happens when a cyber insurance claim is filed, step by step, and explains what your obligations are at each stage. Understanding this process in advance — before an incident occurs — is one of the most valuable preparations a business can make.

Step One — Immediate Notice to Your Insurer

Nearly every cyber insurance policy contains a notice requirement: the insured must notify the insurer promptly after discovering a cyber event. What “promptly” means varies by policy. Some policies say “as soon as practicable,” which courts interpret as meaning within a reasonable time under the circumstances. Others specify a concrete window — 24, 48, or 72 hours, or sometimes a number of days. Whatever the specific language, failure to provide timely notice is one of the most common grounds for coverage denial, and it is almost entirely preventable.

One of the more contested questions is when “discovery” actually occurs. Does the clock start when an IT employee notices an anomaly in system logs? When leadership is formally informed? When the full scope of the incident is understood? Policies and courts differ on this, but the safe practice — the one that best protects your coverage — is to notify your insurer at the earliest reasonable point, even if you do not yet know the full extent of what happened. Waiting until you have a complete picture before notifying is exactly when notice becomes “late” in the eyes of an insurer or a court.

There are three parties who should be in the loop from day one. First is the insurer itself, which will have a 24/7 claims hotline listed in your policy — this number should be saved somewhere accessible before any incident occurs, not buried in documents that may be on an encrypted server during a ransomware attack. Second is your insurance broker, who can help navigate the initial process and advocate for you. Third is your outside legal counsel, who can help you understand your obligations and protect your legal position from the very first communication with the insurer. Ideally, you notify your attorney first, and then the insurer and broker together, with the attorney guiding what is communicated.

Step Two — Insurer-Approved Vendors and the Response Team

Cyber insurers do not simply cut a check and let you handle the response on your own. They maintain panels of pre-approved, pre-vetted vendors who handle every component of incident response: forensic investigation firms that conduct the technical investigation, breach counsel law firms that manage legal obligations, public relations agencies that handle communications, and notification vendors that execute the legally required notifications to affected individuals. Most policies require that you use these approved vendors for covered services, and using a non-approved vendor without prior written authorization from the insurer can result in those costs not being reimbursed.

This is a source of real friction for businesses that have existing relationships with their own IT consultants, law firms, or PR agencies. The insurer’s approved panel vendors have negotiated rates with the insurer and have been vetted for quality and reliability in cyber incident contexts. If you want to use a vendor outside the panel — for example, a forensic firm you have a longstanding relationship with — you must get explicit written authorization from the insurer before engaging that vendor. Without that authorization, the cost may be yours to bear regardless of what your policy says about coverage.

The insurer will typically appoint or approve a breach counsel attorney from its panel who becomes the legal coordinator for the incident response. This attorney manages the investigation timeline, advises on notification obligations under applicable state and federal law, interfaces with the insurer, and often acts as the project manager for the entire response effort. If you retained your own legal counsel before notifying the insurer, that attorney should remain in the picture — but their role becomes coordination with, not replacement of, the insurer-appointed counsel. Your own counsel’s primary value in this context is representing your interests, particularly if coverage disputes arise.

Step Three — The Investigation and Coverage Determination

Once the response team is assembled, the forensic investigation begins. The forensic firm’s job is to determine what happened: which systems were compromised, how the attacker gained initial access, what data was accessed or exfiltrated, when the event began (which may be weeks or months before it was detected), and whether the attacker’s presence has been fully eliminated. This investigation is the technical foundation of everything that follows.

The investigation drives two parallel processes simultaneously. The first is legal compliance: based on what data was involved, the breach counsel attorney determines what breach notification laws apply, which affected individuals must be notified, which regulators must be informed, and what the applicable deadlines are. This process can begin generating legal obligations before the investigation is even complete. The second process is the insurance coverage determination: the insurer reviews the investigation findings and maps the facts to the policy’s coverage grants, exclusions, and conditions to determine which losses are covered and in what amounts.

During this phase, the insurer may issue a “reservation of rights” letter. Understanding what this letter means — and how to respond to it — is one of the most important things a business owner can know about the cyber claims process.

Reservation of Rights — What It Means and Why It Matters

A reservation of rights letter is a formal communication from the insurer that says, in essence: “We will provide you with defense costs or coverage for now, but we reserve the right to deny coverage later once we have more information.” It is not a denial — coverage is still being provided in the moment. But it is a serious warning sign that the insurer has identified one or more potential grounds on which they might ultimately deny coverage.

Common reasons an insurer issues a reservation of rights in a cyber claim include: a question about whether the loss was caused by an event excluded from coverage (such as the war exclusion or a prior-known-circumstances exclusion); an investigation into whether the insurance application contained material misrepresentations about the business’s security practices; uncertainty about whether the specific loss falls within a particular coverage grant; or a timing issue about when the event occurred relative to the policy period. In other words, the insurer is telling you that coverage is in question while simultaneously continuing to provide it — for now.

If you receive a reservation of rights letter, you should contact your own independent attorney immediately. Here is why: the breach counsel attorney appointed by the insurer may have a conflict of interest in this situation. That attorney is paid by the insurer, coordinates with the insurer, and operates within the insurer’s framework. If the insurer is simultaneously defending you and investigating grounds to deny your claim, the insurer-appointed attorney’s interests may not be fully aligned with yours. Your independent attorney — retained by you, paid by you — can evaluate the reservation of rights letter, advise you on your rights, and represent your interests if the coverage dispute escalates.

Your Duty to Cooperate — And Its Limits

Cyber insurance policies impose a duty to cooperate on the insured. This means you are obligated to provide the insurer with access to your personnel, systems, documents, and records relevant to the claim. It means you cannot settle any third-party claims — lawsuits brought by customers, vendors, or others who were harmed by the incident — without the insurer’s prior written consent. It means submitting to an Examination Under Oath if the insurer requests one, which is a formal proceeding where an insurer’s attorney questions you under oath about the facts of the claim. And it means not making voluntary admissions of liability that could increase the insurer’s exposure.

Non-cooperation is a real basis for claim denial. Insurers who can demonstrate that the insured failed to provide requested information, concealed material facts, or refused to participate in the investigation can void coverage on that ground. The cooperation obligation is taken seriously, and business owners should take it seriously too.

That said, there are important limits. The cooperation obligation does not require you to waive attorney-client privilege. Communications between you and your attorney about the incident are protected, and the insurer cannot compel you to disclose them. You are also entitled to receive independent legal advice about your obligations before responding to insurer demands — particularly if a reservation of rights is in play. If you are ever uncertain whether a specific insurer demand falls within your cooperation obligation or crosses into territory that could prejudice your legal rights, that is precisely the kind of question to bring to your own independent attorney before responding.

Settlement and Claim Resolution

Once the investigation is complete and covered losses have been established, the insurer pays covered amounts up to the applicable policy limits, minus any retention or deductible. For first-party losses — your own costs for responding to the incident, including forensic fees, notification costs, credit monitoring, and business interruption — this process is relatively straightforward once the facts are established. The insurer reviews the documented costs, confirms they fall within the coverage grants, and pays within the limits.

Third-party claims — lawsuits filed by affected customers, regulatory enforcement actions, or demands from business partners — are handled differently. In these situations, the insurer typically controls the defense through the appointed breach counsel, and the policy requires the insurer’s consent before any settlement is reached. This means some degree of control over litigation strategy effectively shifts from you to the insurer. The insurer may push for a settlement that resolves the matter at minimal cost even if you believe your legal position is stronger and you would prefer to litigate. Your rights in this situation are limited, but your independent counsel can help you understand them and advocate for your position with the insurer.

If your claim is denied — in whole or in part — that is not the end of the road. A claim denial is the insurer’s position, not a final legal determination. You have the right to challenge the denial. Depending on the circumstances, your options include demanding a formal explanation, engaging in the policy’s internal dispute resolution process, or filing a lawsuit against the insurer for breach of contract. In cases where the insurer has acted unreasonably or in bad faith — for example, denying a clearly covered claim without adequate investigation — some states allow policyholders to pursue insurance bad faith claims that go beyond the policy limits. If you receive a coverage denial on a significant claim, getting an attorney involved immediately is not optional.