What cyber insurers actually check at claim time

At claim time, the insurer compares what you said on the application with what the investigation finds: whether MFA, backups and endpoint detection were really in place, and how the attacker got in. It also checks that you followed the policy’s own rules — prompt notice, its panel of responders, and its consent before you spent money. Most claim friction comes from those two gaps, not from the attack itself.

How are your application answers tested?

The application answers become the yardstick. After a serious incident, a forensic firm reconstructs how the attacker got in and what was running at the time. That report tends to answer, precisely, the questions the application asked:

  • MFA. Was it enforced on the account or remote-access path the attacker actually used — including the old appliance kept for one supplier?
  • Backups. Did an offline or immutable copy exist, and did it restore? Encrypted backups on the same domain credentials tell their own story.
  • Endpoint detection and response. Was the agent on the machines involved, and did anyone respond to its alerts?
  • Patching. Was the exploited flaw one with a fix already available?

The insurer will read the forensic findings next to your application, and a gap can put the claim in dispute. How your policy and the law treat that gap is a question for your broker and counsel, and it is worth asking before renewal. The honest-answer side of this is in what cyber insurance applications ask, and how to answer.

Which policy conditions can sink a claim?

A claim can run into trouble with perfect controls, because the policy has rules about how you respond. Read your wording for these four before you need them:

ConditionWhat it usually means in practice
NoticeReport a suspected incident promptly, often through a named hotline, rather than once you are sure.
Panel respondersBreach counsel, forensics and negotiators chosen from the insurer’s list, or approved in advance.
Consent to costsNo significant spending, and no payment to an attacker, without the insurer’s agreement first.
CooperationAccess to records, people and findings while the claim is assessed.

Can you use your own incident response firm? Sometimes, but only with the insurer’s agreement. Many policies name a panel and expect you to use it; if you want your own firm, get it approved in writing, ideally at renewal rather than during an incident.

Can preparation wait because the insurer runs the response?

No. The panel brings skilled people, but they arrive knowing nothing about your estate. What they can prove depends on what you kept. Logs that rolled over after a few days, a server rebuilt to “get back up”, or a timeline nobody wrote down will all weaken the claim, however good the responders are.

Three things matter most in the first hours:

  • Preserve evidence before containment destroys it: isolate rather than wipe, and extend log retention. See preserving evidence after a breach.
  • Keep a decision and cost log. Who decided what, when, and what it cost. Claims are paid on records, not on memory.
  • Route third parties through counsel and the insurer, so engagements are approved before anyone starts billing.

NIST’s incident response guidance, SP 800-61 Revision 3 (April 2025, the current revision as of September 2026), treats this preparation as part of ordinary risk management rather than a separate emergency activity, which is the right frame for it.

What should you do before renewal?

  1. Re-check every application answer against the whole estate, and keep the dated evidence.
  2. Put the hotline, notice terms and panel process into your incident plan, word for word.
  3. If you want your own responders, get them approved in writing now.
  4. Rehearse the first hour once, with the policy on the table.

What should be ready before an incident? A dated evidence file behind every application answer, the insurer’s hotline and notice terms in your incident plan, and a named person who records every decision and every cost from the first hour. Where the question is broader — what to retain, what to transfer, and what to fix first — it belongs in enterprise risk management and cyber insurance readiness. Forensic work itself is delivered with appropriately licensed partners where the law requires it.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

Investigation and forensic work is delivered with appropriately licensed partners where the law requires it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

What do cyber insurers look at when we make a claim?

Two things: whether the controls you described on the application were really in place when the attacker got in, and whether you followed the policy’s own conditions on notice, choice of responders and consent to costs.

Can we use our own incident response firm instead of the insurer’s panel?

Sometimes, but only with the insurer’s agreement. Many policies name a panel and expect you to use it; if you want your own firm, get it approved in writing, ideally at renewal rather than during an incident.

What if the investigation shows our application answers were wrong?

The insurer will read the forensic findings next to your application, and a gap can put the claim in dispute. How your policy and the law treat that gap is a question for your broker and counsel, and it is worth asking before renewal.

What should we prepare now, before any claim?

A dated evidence file behind every application answer, the insurer’s hotline and notice terms in your incident plan, and a named person who records every decision and every cost from the first hour.

How do you get ready before a claim?

Send your policy wording, your last application and your incident plan. The reply says where they disagree with each other. Nothing here is legal advice; coverage questions go to your broker and counsel. More of our writing is at writing.

Discuss a scope