Updated in July 2026
Summary of the claims process
The following numbered steps give the quick overview a decision maker needs. Each step states the outcome to expect and the likely timing.
Initial report and acknowledgement
The policyholder notifies the insurer on the same day the incident is discovered. Most UK insurers acknowledge within hours. They give a claims reference to start the response.
Insurer acknowledgement helps protect cover under applicable insurance law and policy notification terms. This starts formal records and helps with later validation.
This short checklist helps when time is tight.
The insurer or breach coach contacts the policyholder within 24 to 48 hours on standard SME panels. Forensic triage then begins. Urgent costs may be authorised to limit further loss.
Fast contact often reduces business interruption and evidence loss. A named contact speeds decisions for emergency hires and legal advice.
Act quickly when the breach coach calls.
Validation
The claims handler validates evidence and confirms covered costs within 30 to 90 days. Insurers may pay interim sums for urgent invoices. Final settlement and any subrogation follow, often by day 300 for typical SME claims.
The insurer checks invoices against the policy wording and limits. Clear documents shorten this phase and cut delays.
Expect routine questions on scope and necessity.
Step 1: detect, preserve and notify
Detect the incident and preserve all evidence on day 0. Early evidence capture avoids gaps that delay or void claims.
Preserve logs and snapshots
Collect server logs, backup metadata and screenshots immediately. Keep original files read-only and do not overwrite them. Note who accessed what and when in a simple timeline.
Make a copy for investigators and keep originals untouched. This prevents later challenges over altered evidence.
Notify your insurer the same day
Call the insurer 24/7 incident line or contact your broker and record the call details. Say only verifiable facts: when detected, systems affected and whether extortion is alleged. Ask for the claims reference and breach coach contact.
Record the time and name of the person you speak to. This proves early notification if cover is questioned.
Practical first-hour checklist
Stop systems only if an IT adviser or breach coach tells you to do so. Avoid speculative statements in external messages. Keep a running timeline of actions and decisions from day 0.
Do not delete files or overwrite logs while you work. Preserve evidence even if restoration seems urgent.
Step 2: contain, triage and appoint experts
Containment and triage usually occur during days 1 to 7. How quickly this happens controls how quickly the claim moves and how much loss accrues.
Breach coach and forensic panel
Insurers normally supply a breach coach or panel forensic investigator. Accepting an approved panel speeds evidence validation and payment. Ask for an SLA on first contact time and on forensic report delivery.
Using an approved provider can avoid scope disputes later. The claims handler trusts panel reports when they follow accepted formats.
Legal, PR and regulatory triage
Legal counsel and PR advisers help manage ICO notification and press risk. Data protection law may require notification to the ICO within 72 hours. See ICO guidance for details.
Regulatory work often lengthens the claim timeline. Keep legal bills separate and submit them early for interim payment.
Early cost signalling
Compile urgent invoices for forensics, legal and temporary IT contractors. Submit these early for interim payment consideration. Keep receipts and supplier contact details.
Early signalling helps the insurer prioritise cash for immediate needs. It also reduces the chance of critical suppliers stopping work.
Step 3: validation, interim payments and business interruption
Claim validation and interim payments normally cover days 30 to 90. Clear documentation reduces disputes and speeds cash flow.
Forensic and legal cost validation
The claims handler, loss adjuster or assessor checks invoices and forensic reports. Insurers compare costs with policy wording, sub-limits and excess. Expect questions on scope and necessity.
Provide clear scope notes on why each cost was needed. This saves back-and-forth and speeds interim payments.
Business interruption calculation
Business interruption uses declared turnover or net profit and an agreed indemnity period. The insurer asks for payroll, sales data and evidence of interrupted activity. The calculation may need an independent accountant.
Provide month-by-month sales and payroll extracts for the indemnity period. This helps reach a robust BI figure faster.
Interim payments and final settlement
Insurers often pay interim sums for urgent costs while the full claim is validated. Final settlement normally follows full accounting and any subrogation steps. Allow up to 300 days for complex claims with regulatory or criminal enquiries.
Interim payments keep trading while forensic and legal work continues. Final amounts adjust after a full review and any recoveries from third parties.
This estimate helps plan cashflow and supplier payments.
Errors that ruin your claim
The most common mistake is waiting to notify the insurer while trying to fix the problem alone. Late notification often causes cover disputes and delays.
Missing or altered evidence
Submitting incomplete logs or edited screenshots invites challenges from the claims handler. Keep original copies and make working copies for investigators.
If files look edited, expect detailed questions and possible rejection of some costs.
Authorising payments without consent
Paying ransom privately can breach policy conditions when prior insurer consent is required. Ask for written consent from the insurer or legal counsel before any payment.
Unapproved ransom payments risk repudiation of the whole claim.
Admitting liability or speculation
Communications that admit fault can affect third-party liability lines. Keep messages factual and short until legal counsel advises.
Let legal counsel draft any statement that touches on liability.
Practical next steps and payout estimator
This section gives clear actions and a simple estimator to approximate likely payout. Use it to decide if a claim is worth pursuing or to set cashflow plans.
Three actions to start now
Notify the insurer and record the call and time. Preserve logs and invoices and assemble a short incident timeline. Request the name and SLA of the breach coach and claims handler.
These three steps open the claim and speed interim funding.
Simple payout estimator
The estimator below shows how sub-limits and excess change net payout.
- Policy limit: £250,000
- Excess: £5,000
- Sub-limit for ransom: £50,000
- Costs claimed: Forensic £12,000; Legal £8,000; Ransom £60,000; BI £40,000
Calculation:
- Ransom allowed by sub-limit: £50,000
- Total allowed costs: £12,000 + £8,000 + £50,000 + £40,000 = £110,000
- Minus excess: £110,000 − £5,000 = £105,000 payout
This shows why checking sub-limits matters for SMEs.
Payout line-items: realistic ranges
Forensic investigation: £500 to £30,000. Legal and breach coach: £1,000 to £50,000. PR: £500 to £25,000. BI: £1,000 to £200,000 depending on turnover and indemnity period. Ransom sub-limits commonly sit between £25,000 and £250,000.
Key difference: check whether ransom is listed as a covered loss and whether the policy requires insurer consent before payment. This single clause often decides net recovery and legal risks.
Insurer comparison table
| Insurer |
24/7 line |
Breach coach SLA |
Ransom sub‑limit |
BI indemnity period |
| Hiscox |
Yes |
24–48 hrs |
£25k–£150k |
3–12 months |
| Aviva |
Yes |
24 hrs |
£50k–£250k |
3–12 months |
| AXA |
Yes |
48 hrs |
£25k–£100k |
3–6 months |
| Chubb/Lloyd's panels |
Yes |
24 hrs |
£50k–£250k+ |
6–12 months |
Timeline day 0 → 300
Day 0. Detect & Notify
Preserve evidence, call insurer
Days 1–7. Contain & Triage
Breach coach contact, forensics start
Days 30–90. Validate & Interim Pay
Loss adjuster assesses invoices
Days 90–300. Settlement
Final payout, subrogation and close
Anonymised payout case studies
Example 1. Retail SME (ransomware): A small retail business suffered a ransomware attack. The extortion demand was £60,000 on day 1. Insurer ransom sub-limit was £50,000 and policy excess was £5,000.
Forensic triage cost £8,200 (day 2–7). Legal fees were £3,400 (day 7–30). Temporary IT contractors cost £6,800 (days 7–45). BI losses were £24,000 over a four-week indemnity period.
The insurer authorised an interim payment of £25,000 at day 40. Final net payout was £86,000 after sub-limit and excess adjustments. Subrogation enquiries continued after settlement.
Example 2. Professional services SME (data breach): A small consultancy detected unauthorised access to client data. Defence costs totalled £18,500 and ICO work pushed timescales past 120 days. An interim payment of £7,500 arrived at day 35 to fund urgent legal advice.
The insurer declined regulatory fines but paid defence and PR costs. The final paid sum was £15,200 after validation and deductions.
These anonymised examples show how interim payments, sub-limits and excess change net recovery and timelines.
When this method does not apply
This method does not apply if the business has no cyber policy, the incident predates the policy retroactive date, the loss arises from deliberate fraud by the insured, or the loss falls below the policy excess. In these cases the insurer will not pay and an alternative route must be used, such as self‑funding or specialist legal action.
If the incident involves suspected internal criminality by an employee, insurers often exclude cover. Check policy wording and speak to legal counsel swiftly. A typical case saw a single-director retail SME delay notification and then face declined costs.
If a crime is ongoing and evidence may be part of a police inquiry, preserve data but avoid deleting potential evidence. Notify the insurer and police promptly and record all communications.
If the loss is only reputational without demonstrable financial harm, some policies do not pay unless third-party liability or clear BI exists. Read the indemnity terms carefully before submitting an expectation of payout.
If unsure, contact your broker and provide the claim template below when you call the insurer.
Frequently asked questions
How quickly should I notify the insurer?
Notify the insurer on the same day you discover the incident. Early notification preserves cover and speeds response. Insurance Act 2015 obligations mean delays can affect cover.
Do I have to report to the ICO and when?
You must report to the ICO when GDPR and the DPA 2018 require it. The 72-hour rule applies when personal data breach risk is likely to cause harm. Seek legal advice if unsure.
What documentation speeds a payout?
A clear incident timeline, original logs, supplier invoices and payroll or sales records for BI speed validation. Missing evidence is the top cause of delays and disputes. Provide originals as read-only copies.
How long will a payout take for a business?
Interim payments may arrive within 30 to 90 days for urgent costs. Final BI settlement often takes longer, sometimes up to 300 days for complex claims with external audits. Plan cashflow for this timescale.
Can an insurer claw back payments later?
Yes. If the insurer finds non-disclosure, fraud or incorrect evidence the insurer can claw back payments. Keep accurate records and be transparent during the claim.
Will the insurer pay a ransom?
Some policies cover ransom but often with a specific sub-limit and conditions. The insurer may require prior consent and use of an approved negotiator. Paying outside these terms risks repudiation at validation and subrogation stages.
Closing checklist and templates
The blocks below can be copied into an email or printed for your broker or insurer. Use them to start the claim immediately.
Short incident notification email
Subject: Cyber incident notification - [Company Name] - [Date]
Policy number: [policy number]
Claims contact: [name]
Summary: On [date/time] [brief factual description of what happened]. Systems affected: [server/email/EPOS]. Personal data involved: [yes/no]. Extortion demanded: [yes/no]. Immediate steps taken: [disconnect/isolated/backups preserved].
Attached: incident timeline, initial screenshots, contact details for person handling this incident.
Please confirm receipt and provide breach coach contact and claims reference.
Regards,
[Name] - [Role] - [Phone]
Claim submission checklist
- Incident timeline with timestamps and actions.
- Original logs and forensic snapshots (read-only copies).
- Invoices for urgent costs (forensic, legal, PR, temporary staff).
- Sales, payroll and bank records for BI calculation.
- Copies of the extortion demand or attack screenshots.
- Contact details for staff and suppliers involved.
Date | Supplier | Cost type | Amount | Receipt attached (Y/N) | Notes
2024-05-01 | Forensics Ltd | Forensic | £4,200 | Y | Initial triage
Final remark: The legal background matters: the Insurance Act 2015 and GDPR (Data Protection Act 2018) shape insurer obligations and regulatory duties. Check policy wording and ask underwriters for any unclear clauses.
Compact claim submission checklist
Claim submission checklist:
- include policy number and broker details
- earliest detection timestamp and short factual incident summary
- systems affected and short technical indicators
- clear incident timeline with timestamps of detection, isolation and key actions
- original logs and read-only forensic snapshots (location and hash)
- supplier invoices for forensic triage, legal, PR and temporary IT
- proof of interim payments already made and bank or receipt copies
- payroll, sales and accounting extracts covering the indemnity period for any BI cover
- copies of extortion demands or attacker communications
- contact details for internal incident lead and external advisers (forensic firm, legal counsel, PR)
- statement on whether ICO notification is expected and any police reference number
- list of any immediate remedial costs requested as interim payment
Attaching this single block of items speeds claim validation and interim payment assessment.
Will the insurer pay a ransom?
Some policies cover ransom but often with a specific sub-limit and conditions. The insurer may require prior consent and the use of an approved negotiator, and criminal or legal risks can apply.
Who pays for regulatory fines?
Most UK cyber policies cover defence costs but exclude fines and penalties. Check policy wording, as cover for fines is rare and often excluded by law.
Legal and fiscal clarity on ransomware payouts
Ransomware payouts sit at the intersection of insurance cover, criminal law and tax rules. Many UK policies will cover a ransom only up to a stated sub-limit and usually require prior insurer consent and use of an approved negotiator. Payments to entities on sanctions lists can be a criminal offence under OFSI rules and can halt parts of the claim process while evidence is preserved.
Given these consequences, log the decision process, obtain written consent from the insurer before any payment, and record any use of an approved negotiator to evidence compliance during claim validation.