Has a breach hit or is one looming?
Many small UK firms find the first hours chaotic: unclear insurer obligations, lost evidence and regulators expecting swift action.
SME owners, directors or sole traders often lack cyber and insurance know-how.
Rapid practical steps reduce downtime and the chance of claim refusal or fines.
Follow the ordered steps that begin by contacting the insurer or broker within hours.
Process summary
This section gives a short, ordered list of actions to take now and what each delivers.
- Contact the insurer or broker within hours: secure an acknowledgement and a claim reference.
- Contain affected systems and preserve evidence: this protects forensics and policy compliance.
- Engage an accredited forensic investigator if required: capture images and maintain chain of custody.
- Notify the ICO within 72 hours if personal data breach risks individuals and gather the regulator report fields.
- Collect business records to substantiate interruption losses and remediation invoices.
What this summary delivers
The summary puts the immediate priorities in order so the business can act without delay.
It reduces the chance of disputes about late notice and lost evidence.
A short ordered plan helps staff act fast and stay aligned.
Quick citable facts
The ICO expects notification within 72 hours when a breach risks individuals (Data Protection Act 2018).
The Insurance Act 2015 affects disclosure duties at placement.
Notify insurers and regulators; contain affected systems
Notify the insurer or broker immediately.
Create a precise incident time log to secure a claim reference and early guidance.
Call the insurer's emergency number and your broker.
Record the exact time of contact and the insurer's claim reference.
Contain affected systems by isolating them from the network.
Document each step with timestamps and who authorised it.
Disconnect affected devices from the network and isolate backups if safe to do so.
Do not delete logs or reinstall systems.
Do not instruct staff to sweep devices for malware.
Give the insurer the policy number and a brief factual incident summary.
State the types of data affected and whether personal data is likely involved.
Keep the initial statement short and factual.
Reporting to the ICO and other bodies
If the breach is likely to result in a risk to individuals, report to the ICO within 72 hours.
Include required fields in your report.
These include a contact point, a breach description and the categories of personal data.
Also give an estimated number of records or people affected and the measures taken to mitigate the breach.
See ICO guidance: https://ico.org.uk/for-organisations/report-a-breach/
Consider reporting criminal acts to Action Fraud.
Report high-impact or national-interest incidents to the NCSC.
Contractual notices to customers
Check supplier and client contracts for required notice windows (often 24–72 hours).
Follow those timelines to avoid breach of contract claims.
⚠️ Do not delay insurer notification or admit fault publicly.
That often triggers policy disputes.
Do not assume an automatic ICO exemption.
If personal data could cause harm or distress, the ICO expects a report within 72 hours.
Step 2: evidence and forensics
Secure and preserve evidence.
Instruct a qualified forensic investigator to capture images and give a signed report that insurers accept.
Collect initial logs, screenshots and a basic timeline before any system changes.
These items support both insurer review and ICO reporting.
Ask for a forensic image (bit-for-bit copy).
Ask for a written report that lists hash values, describes steps taken and includes a signed chain of custody.
Choosing a forensic provider
Prefer a firm with CREST membership or ISO 17025 accreditation.
Choose one with a clear chain of custody process.
Insurers often require accredited providers.
Chain-of-custody essentials
Record the collector name, collection time and item ID.
Record the storage method, hash or checksum, transfer receipts and signatures.
Estimated forensics window and cost: initial triage 24–72 hours; full analysis 3–21 days.
Typical SME forensic costs range from £2,000 to £15,000 depending on complexity.
1. Notice
Contact insurer and record time
2. Contain
Isolate systems and protect backups
3. Forensics
Accredited capture with chain of custody
4. Regulator
Decide ICO/Action Fraud/NCSC reporting
5. Losses
Collect ledgers, invoices and BI records

Step 3: costs, timelines and estimates
Use a simple phase matrix to estimate how long each claims stage takes.
Use it to estimate typical costs for SMEs.
Typical durations: initial acknowledgement 0–72 hours.
Forensic analysis 3–21 days.
Insurer cost authorisation can take days to weeks.
Settlement can take two weeks to more than six months.
Typical cost bands for SMEs: forensic £2k–£15k.
Legal and PR costs £1k–£10k.
Business interruption usually equals lost weekly turnover.
Phase decision table
| Phase |
Typical duration |
Decision gate |
Cost band (GBP) |
| Initial notice |
0–72 hours |
Notify insurer |
Minimal |
| Forensic analysis |
3–21 days |
Authorise provider |
£2,000–£15,000 |
| Regulatory report |
24–72 hours (decision) |
Submit ICO report if required |
Minimal to £5k+ |
| Settlement |
2 weeks–6+ months |
Insurer decision or appeal |
Varies by claim |
Cost drivers and tips
Costs rise with more affected systems, the need for specialist recovery, and liability disputes.
Secure contemporaneous sales and payroll records to prove business interruption losses.
An SME retail business struck by ransomware might notify its insurer within two hours.
It may then commission an accredited forensic investigation.
Triage could take 48 hours and the full report ten days.
Immediate forensic and remediation costs might be about £12,000.
The insurer may authorise PR and legal costs of £4,000.
They may accept a business interruption claim for two weeks' lost turnover of about £6,000.
Net recovery after a £2,500 excess would be roughly £19,500 in this hypothetical.
A small professional services firm may have minimal lost turnover.
Its clean-up might need specialist data recovery costing about £6,000.
The firm may also need to file an ICO report.
After excesses and possible premium rises, claiming may be marginal.
These examples show typical incident timelines and spend split.
They also show how claim documentation and chain of custody feed into a successful claim.
Step 5: avoid denials, appeal and policy wording
Address the main causes of denial early.
Collect missing evidence quickly if the insurer raises objections.
Request written reasons for any denial.
Supply additional contemporaneous evidence or an independent expert report to support an appeal.
Negotiate or clarify policy wording around notification and approved providers at purchase or renewal.
Also check ransom cover and any sub-limits to avoid surprises later.
Top denial causes
Top causes are delayed notice and destroyed logs.
They also include using unauthorised providers and undisclosed prior incidents.
Warranty-type exclusions for poor security also cause denials.
Practical appeal steps
Ask the insurer for clause references in any denial letter.
Provide new evidence with chain of custody.
Obtain an independent report.
Escalate via the broker or to the Financial Ombudsman Service.
Policy wording to check
Check for "notification period", "approved providers", "sub-limits for PR/legal", "retroactive date" and whether ransom payments are included or excluded.
First, request written reasons and specific policy clause references for the denial.
Note the date.
Preserve and supply contemporaneous claim documentation.
Include the incident timeline, forensics report with hash values, chain of custody, invoices and payroll or till records.
Second, provide a short written appeal of one to two pages summarising new or previously unshared evidence.
For example, include a CREST-accredited forensic investigation, remediation invoices and supplier statements proving increased costs.
Typical escalation timing starts with the insurer's internal review.
Ask for an expected response window, often 30 to 90 days.
Escalate via the broker in parallel and then make a formal complaint to the insurer.
If unresolved after eight weeks or after the insurer's final response, eligible SMEs can refer to the Financial Ombudsman Service.
They can also consider litigation.
Sample appeal wording could be a crisp factual chronology with explicit policy references.
Attach labelled exhibits such as "Forensic report – Exhibit A" to help decision-makers verify documentation quickly.
FAQ
How do I claim on cyber insurance?
Contact the insurer or broker immediately and give the policy number and a concise incident summary.
Preserve evidence and follow insurer instructions.
Insurers usually expect first notice within hours, followed later by a written claim form.
What does cyber insurance typically cover?
Typical cover includes forensic costs, notification, PR, legal fees, business interruption and third-party liability.
Cover sits subject to limits, excesses and sub-limits shown in the policy schedule.
How quickly must I notify the ICO?
Notify the ICO within 72 hours if the breach is likely to result in a risk to people.
Provide required fields such as contact point, breach nature and mitigation steps (Data Protection Act 2018).
Does cyber insurance cover ransomware payments?
Some policies cover ransom and negotiation costs.
Cover often requires prior authorisation and may carry sub-limits.
Check the ransom section of the schedule before any payment.
What evidence do insurers need for business interruption?
Insurers need contemporaneous records such as sales ledgers, till rolls and payroll records.
They also need supplier invoices that show lost turnover or increased costs during the interruption period.
How long does a claim usually take to settle?
Initial acknowledgement typically arrives within 24–72 hours.
Forensic and insurer approval usually take 3–21 days.
Final settlement ranges from weeks to over six months depending on complexity.
Templates, checklists and resources
This section contains field-ready templates and checklists the policyholder can copy and use immediately.
To: claims@[insurer].com
Subject: Claim notification – Policy [POLICY NUMBER] – [Business name]
Policy number: [POLICY NUMBER]
Claimant: [Business name], contact [Name] [Phone] [Email]
Date/time incident discovered: [YYYY-MM-DD HH:MM]
Short description: [e.g. Suspected ransomware encrypting file servers]
Personal data involved: [yes/no] – if yes, estimated number of individuals [estimate]
Containment steps taken: [e.g. Isolated servers at HH:MM]
Requested action: urgent claims handler and reference number
Please confirm receipt and the next authorised steps.
Chain-of-custody checklist
Item ID:
Collector name:
Collection date/time:
Device/asset serial:
Collection location:
Hash/checksum:
Storage method:
Transfer history and signatures:
Notes:
Forensic vendor shortlist questions
- Are you CREST or ISO 17025 accredited?
- Can you provide a sample report and evidence of previous SME work?
- How long to deliver initial findings and full report?
- How do you store and transfer images to preserve chain of custody?
- Do you sign non‑disclosure and provide fixed fee estimates for phases?
Simple timeline estimator
- Initial notice and ack: 0–72 hours
- Forensic triage: 24–72 hours
- Full forensic report: 3–21 days
- Insurer cost authorisation: days–weeks
- Settlement or dispute resolution: 2 weeks–6+ months
If the incident is pure property damage, deliberate fraud by an employee, or the likely loss is below the policy excess, claiming may reduce renewal options and is often not appropriate.
For urgent support, call the insurer or your broker now and quote the policy number to get immediate claims assistance.
2023 note: the NCSC and ICO continue to publish guidance for incidents; check both sites for the latest updates and sample reporting fields before submitting formal reports.
Deciding whether to notify an insurer is a practical trade-off that should be documented in the incident log. Start by estimating recoverable losses such as forensic fees, remediation, PR/legal and demonstrable business interruption. Compare these against your policy excess and the likely non-monetary impacts. For example, if expected remediation and BI costs total £8,000 and your excess is £2,500, the gross claimable amount is £5,500.
Factor in the potential for increased renewal premiums or higher excess at renewal over the next 2–3 years. Document this short cost-benefit calculation in your incident log and attach the incident timeline and claim documentation so the insurer can judge policy compliance.