A policy can promise cyber response. Only a workable plan shows who calls the insurer, preserves evidence and informs customers at 2am.
A policy promise can expose an evidence gap
A written policy can weaken your position. This happens when promised controls cannot be shown, tested or followed.
An incident-response policy states management intent. An incident-response plan gives instructions on actions, decisions and escalation.
Does the gap cancel your insurance?
No, a missing plan does not automatically cancel cover. Insurers may still examine application answers, notification rules, exclusions and warranty clauses.
A condition precedent may require prompt notification through an insurer breach helpline. Delay can make a claim harder to defend, especially if an attacker remains in the network.
Material misrepresentation means giving an answer that could change an insurer's decision or price. Do not alter past answers after an event. Correct current information honestly and record what changed.
Who carries the decision risk?
The risk sits with the people who must decide quickly. This is usually a director, IT supplier and Data Protection Officer.
One person needs authority to isolate a device or cloud account. Another must notify the insurer. A director may approve emergency spend or customer messages.
Naming an “IT team” without an out-of-hours decision-maker is a common failure. Directors must exercise reasonable care, skill and diligence. An unresolved known gap can become a governance issue.
Clear names matter more than vague job titles.
What proof insurers, auditors and clients expect
Credible readiness shows who acts, who decides, who is called and what is recorded. It also shows how recovery starts.
| Item | What it does | Useful evidence | Common failure |
| Policy | Sets management intent and scope | Approval date and version owner | States intent but no actions |
| Response plan | Sets the sequence from detection to recovery | Named roles, contacts and incident log | Copied template with wrong suppliers |
| Playbook | Gives steps for one event type | Ransomware or data-breach checklist | Treats all incidents alike |
| IR retainer | Pre-arranges specialist response support | Contract, scope and 24/7 contact route | Appoints a provider before insurer consent |
| Tabletop exercise | Tests decisions through a scenario | Attendance list and corrective actions | Discusses the plan but records nothing |
Policy, plan and playbook are different
A policy is a commitment. A plan covers detection through review. A playbook gives steps for one event, such as ransomware or business email compromise.
A business continuity plan helps the firm keep trading. A disaster recovery plan restores systems and data. Neither necessarily covers evidence, legal advice, insurer approval or customer notices.
Evidence that survives scrutiny
Keep simple, current evidence where the incident-response lead and deputy can reach it. They may need it when normal systems are unavailable.
- An approved policy and plan with a version date, owner and review date.
- Named incident-response lead, deputy, director and Data Protection Officer contacts.
- The insurer's 24/7 breach number, policy number and panel-provider instructions.
- A current managed IT provider and Managed Security Service Provider escalation route.
- An incident log template recording time, decision, action and person responsible.
- Backup test records, including whether restoration worked within your required time.
- A tabletop exercise record and corrective actions with named owners.
A panel incident-response provider is selected or approved by an insurer. Many policies expect you to call the insurer first. The insurer may appoint a forensic investigator or breach coach.
Evidence must work during a real outage.
Build response readiness in 24 hours, 30 and 90 days
Close the immediate gap by assigning authority. Save emergency contacts and write first-hour actions.
The first 24 hours
Start with facts, not software purchases. Keep the document available outside the main network.
- Name an incident-response lead, deputy and director who can approve urgent actions.
- Save the insurer's claims line, notification deadline and any panel-use instruction.
- List the managed IT provider, cyber insurer, legal adviser, Data Protection Officer and priority customer contacts.
- Write safe isolation steps. Disconnect affected devices where appropriate, preserve logs, protect backups and do not wipe systems.
- Create an incident log with date, time, source, decision, action and next owner.
- Check whether the policy or questionnaire honestly describes your current capability.
A minimum viable plan should state how staff report incidents. It should name who classifies and contains them. It should say when to call the insurer, preserve evidence, assess personal-data risk, and approve recovery and messages.
By day 30, adapt playbooks for ransomware, suspected personal-data breach and supplier compromise. By day 90, run a 60-to-90-minute tabletop exercise. Record decisions and update the plan.
🛒
Recommended product
A plain-English incident-response handbook can help a director run a useful first exercise. Check that it suits UK insurer contacts and your systems.
- Gives a paper reference if company email or cloud files are unavailable
- Helps structure ransomware, fraud and data-breach tabletop scenarios
- Supports a simple incident log and decision record for audit evidence
View on Amazon →
A cyber incident-response plan needs an operating cycle, not just contacts. Triage confirms known facts, systems at risk, data at risk and immediate business harm. Containment limits spread.
Eradication removes the attacker's foothold. Recovery returns services in a controlled order. A post-incident review records lessons.
Each incident-response playbook should state when an external forensic provider takes over. It should name who approves disruptive action. It should explain how evidence stays safe before devices are rebuilt.
A ransomware checklist and data breach playbook should state the insurer notification route. They should also give the insurer breach helpline. The insurer may direct the choice of specialist.
An incident-response retainer can make specialist support available faster. It must fit the insurer's panel requirements. This matters overnight, when decisions come before full facts.
The first hour often shapes the whole response.
Avoid claim and reporting mistakes in England
Assess evidence and follow policy requirements. Seek specialist advice when needed.
Under UK GDPR, report a personal-data breach to the ICO when it is likely to risk people's rights and freedoms. Report without undue delay. Where feasible, report within 72 hours.
An ICO notification concerns personal-data risk. Insurer notification concerns the policy contract. An NCSC report replaces neither route.
Restored systems do not prove that no breach occurred. Check access logs, affected data and impacted people. Follow insurer and specialist instructions during ransomware, suspected fraud, serious outages or suspected data breaches.
Correct the promise, not the history
Review any policy that claims a capability you do not have. Do not delete past documents or rewrite incident notes.
Keep version history. Correct client questionnaires narrowly. Where suitable, explain the date when improvement began.
A false assurance can create contract risk without an insurance claim.
This guidance matters less only where an organisation has no digital systems, personal data, online services or cyber contract requirements. Such cases are uncommon. It does not replace urgent advice during active ransomware, fraud, suspected personal-data breaches or major service outages.
For a serious incident, create a separate regulatory escalation line. Do not assume an insurer call completes every duty. The NCSC can receive reports of serious UK cyber incidents and may give practical guidance.
An NCSC report does not notify the ICO, a sector regulator or affected contract parties. Organisations under the UK network and information systems regime should map their competent authority. Keep current contact details.
A future Cyber Security and Resilience Bill framework may also affect reporting. Proposed models used initial notices within 24 hours. They used fuller reports within 72 hours.
The exact trigger, recipient and deadline depend on current rules and your sector. Record why you reported, deferred or ruled out a report.
Separate duties can run on different clocks.
Frequently asked questions
Does no incident response plan void cyber insurance?
No, a missing plan does not automatically void cyber insurance. Cover depends on policy wording, application answers, notification conditions and whether the gap affected the claim.
What must an SME incident response plan include?
An SME plan should include named roles, insurer contacts, containment steps, an incident log and recovery decisions. It should cover ransomware, personal-data breaches and supplier incidents.
Do I need to report every cyber incident to the ICO?
No, report to the ICO when a personal-data breach is likely to risk people's rights and freedoms. Where required, UK GDPR says to act without undue delay. Where feasible, report within 72 hours.
Can my IT provider be my incident response team?
Yes, an IT provider can support incident response if its contract defines availability, authority and escalation. Check whether your cyber insurer requires a panel forensic investigator or breach coach.
Should we buy an incident response retainer?
A retainer helps when you need specialist support outside normal hours or handle high-risk data. It does not replace internal decision-makers, current contacts or a tested first-hour process.
What to do next
Compare your policy promise with what staff can do today. Document the truth and close urgent gaps.
What matters most:- A policy is a promise. A tested plan and named people show that the promise can be kept.
- Missing capability does not automatically defeat cover. Inaccurate disclosure and late notification can make claims harder.
- Within 24 hours, appoint decision-makers, save insurer contacts and create an incident log.
- Within 90 days, test the plan and keep corrective actions as evidence.
Learn more
Here are some additional resources on this subject: