A cyber incident can feel urgent enough to demand an instant answer, yet many claims do not move at the speed owners expect. The first questions are usually practical: who must be told, what evidence needs saving, and how long will the business be waiting for a decision while customers, systems or cash flow are already under strain?
A cyber insurance claim usually starts with immediate notification to the insurer, followed by evidence gathering, assessment by a claims handler, and approval of response costs. The process and timelines vary by incident: minor issues may resolve in days, while ransomware, data breaches and business interruption can take weeks or longer if forensic reports, legal input or customer notifications are needed.
What to do first after a cyber incident
The first hour shapes the whole claim. Notify the insurer, save proof, and stop changes that could damage evidence. Most delays begin here, not at the review stage.
Who to notify in the first 60 minutes
Call the insurer’s claims line or incident response number straight away. If the policy gives access to a claims handler, that person usually becomes the traffic controller for the case.
That matters more than most owners expect. The claims handler often coordinates forensics, lawyers, restoration, and communication, so the claim does not move in a straight line from “problem found” to “money paid”.
If the incident looks like ransomware, a data breach, or business email compromise, treat it as urgent from the start. Many policies expect notice as soon as reasonably possible, and waiting until the next day can create questions that are hard to unwind later.
The fastest claims usually begin with a short, clear notice: what happened, when it was found, what systems are affected, and who is already involved.
What not to do before approval
Do not wipe devices, rebuild servers, or delete messages before the insurer or the appointed specialists say it is safe. That is like throwing away the broken lock before the police have photographed the door.
This is where many small businesses stumble. A quick repair feels sensible, but the wrong fix can remove the evidence the insurer needs to validate the claim.
A case that comes up often: a business restores email too early, loses the login trail, and then spends days trying to prove the scale of the compromise. The technical fix was fast. The claim became slow.
Save emails, screenshots, logs, invoices, phone notes, and the exact time the problem was found. Keep a simple incident note with dates, names, and actions taken.
If staff called a supplier, an IT provider, or a lawyer, keep those details too. The claim file often grows out of these early records, not from the final report.
This step usually takes 10 to 20 minutes if someone is calm and organised. It takes much longer if a team has already started changing systems and nobody knows what happened first.
A practical process usually follows the same sequence, even when the facts are messy. First comes notification to the insurer, then a coverage check against the policy wording, then evidence gathering with the claims handler and any incident response team. After that, the insurer may appoint forensic specialists, ask for a forensic report, and agree urgent restoration costs where needed. Only then does loss assessment begin in earnest, followed by final settlement or partial payment.
For example, a small mailbox compromise may move quickly because the evidence is simple, while a wider data breach can stay open until customer notifications, legal review, and technical findings all line up. The key is that each step depends on the last one being documented properly.
How a UK cyber claim is assessed
The insurer checks three things first: whether the event is covered, whether notice was given on time, and whether the costs match the policy. If one of those is weak, the claim slows down fast.
What the insurer checks first
The claims team usually asks for the date of discovery, the systems affected, the type of attack, and the immediate loss. They also check whether the event fits the wording in the policy.
That wording matters. A cyber policy may cover restoration, forensics, notification, extortion, or business interruption, but not every policy covers every loss. The cover is more like a menu than a blanket.
The Association of British Insurers’ cyber insurance guidance is clear that businesses should read notification duties and exclusions carefully before a loss happens.
The insurer is not only checking the damage. It is checking whether the claim fits the policy word for word.
Why exclusions and limits matter
Exclusions decide what the policy will not pay for. Limits decide the most it will pay, even when the claim is valid.
That sounds obvious, yet it is where many owners get caught out. A breach may be covered, while a contract penalty, system upgrade, or pre-existing issue may not be.
Policy excess also matters. If the loss is below the excess, there may be nothing to pay, even if the incident was real and painful.
When a claim is turned down
Claims are often declined or reduced when notice is late, evidence is missing, or the loss falls outside the wording. Sometimes the claim is valid in principle, but the paperwork does not prove it.
The quieter failure is poor chronology. If nobody can show what happened first, the insurer may struggle to separate the covered event from later cleanup work.
That is why good claims move like a tidy paper trail. Every step should answer a simple question: what happened, when did it happen, and what cost followed from it?
Claims timeline: what happens and how long it takes
Most claims do not settle in one block. They move through notice, triage, investigation, cost approval, and closure. The full timeline can be a few days or several weeks.
Minor incidents
A small incident with clear facts can close in 3 to 10 working days if the evidence is complete and the cost is low. Think of a limited mailbox compromise, a contained malware event, or a small recovery bill.
These claims move fastest when the insurer sees a clean story. One event. One loss. One invoice trail.
In recent years, claims teams across the UK have continued to report that missing timestamps and incomplete screenshots are among the main reasons small claims take longer than expected.
Ransomware and extortion
Ransomware and extortion claims usually take 2 to 6 weeks, and longer when negotiation, decryption, or wider system recovery is involved. The insurer may need legal input before any response moves ahead.
The delay is not just technical. It is also about risk, proof, and timing. A claims handler may wait for a forensics report before approving restoration or payment decisions.
The UK National Cyber Security Centre advises businesses to preserve evidence and avoid rushed changes after an attack, because the early response can affect both recovery and later investigation. National Cyber Security Centre guidance
Data breaches and BI
Data breaches often take 2 to 8 weeks when personal data, customer notice, or regulatory review is involved. If the incident reaches the Information Commissioner’s Office, the case can stretch further.
Business interruption claims can take even longer. The insurer must confirm the cause, the duration, the waiting period, and the financial loss. That proof usually comes from finance records, not just IT logs.
A breach may be technically fixed in a day, but the claim can stay open for weeks if the business must prove who was affected, what data was exposed, and what extra cost followed.
The claim ends when the insurer can match the incident, the cover, and the loss. If any one of those is fuzzy, the timeline grows.
| Incident type |
Typical claim speed |
What slows it down |
What to prepare |
| Minor malware or mailbox issue |
3 to 10 working days |
Missing logs, unclear loss, delayed notice |
Screenshots, timestamps, invoices |
| Ransomware or extortion |
2 to 6 weeks |
Forensics, legal review, recovery sequencing |
System logs, ransom note, incident notes |
| Data breach |
2 to 8 weeks |
Notification duties, customer impact, ICO review |
Affected data list, breach timeline, notices |
| Business interruption |
3 to 12 weeks |
Waiting period, revenue proof, loss calculation |
Accounts, sales records, downtime proof |
“The legal deadline to notify a personal data breach to the ICO is 72 hours, where feasible.”
That 72-hour rule comes from the UK GDPR framework, and it matters because cyber claims often run alongside regulatory duties. ICO breach reporting guidance
Timelines vary sharply by incident type. A minor claim may close in a few working days if there is a clear coverage check and little dispute over costs, but ransomware often takes several weeks because the insurer may need legal input, a forensic report and careful sequencing of incident response actions. A data breach usually takes longer again when customer notifications, regulatory reporting and liability questions are involved. Business interruption is often the slowest category because the insurer must compare pre-loss and post-loss trading figures, confirm the period of interruption and test whether the loss really flowed from the cyber event.
Delays also happen when notice is late, evidence is incomplete, or the business starts restoration before approval.
Why business interruption claims take the longest
Business interruption claims take longer because they turn technical failure into a money problem. The insurer has to prove not only that the system went down, but also what income was lost because of it.
What the waiting period actually does
The waiting period is the time after the outage starts before cover begins to pay. It works a bit like a car insurance excess in time rather than pounds.
If the waiting period is 12 hours and the system comes back after 10, there may be no BI payment at all. If the outage lasts longer, the insurer still needs exact timing before it starts the calculation.
That is why some apparently small incidents become awkward claims. The outage might feel severe, but the policy clock decides whether the loss is covered.
What proof of loss the insurer wants
The insurer usually asks for accounts, order records, payroll, cancelled invoices, and a clear note of what stopped trading. It may also ask for cashflow evidence before and after the incident.
That means the finance side matters as much as the IT side. A clean forensics report helps, but it does not replace proof of lost income.
In practice, this is where many SMEs slow themselves down. They can show the outage, but not the pounds lost because of it.
How downtime becomes a money claim
The claim turns from “systems were down” into “here is the financial effect of that downtime”. That gap is where most BI investigations spend time.
If staff worked manually, shifted orders, or used a backup channel, the insurer will want to know whether the loss reduced. If trading recovered quickly, the final payment may be much smaller than expected.
The key phrase is simple: the insurer pays for loss caused by the event, not for every inconvenience that followed.
What documents speed up the claim
The best checklist is the one that helps a claims handler say yes without chasing extra proof. Keep the incident file tidy from day one.
Your evidence-preservation checklist
Keep these items together in one folder, even if the folder is shared across email and cloud storage:
- incident date and discovery time
- screenshot of the error, ransom note, or breach alert
- affected device, account, server, or service names
- first response notes and who took action
- system logs, access logs, and email headers where relevant
- copies of any ransom demand or threat message
- invoices for emergency IT, forensics, legal, or recovery work
- proof of downtime, lost orders, or delayed service
- copies of insurer emails and claim reference numbers
This step usually takes 15 to 30 minutes if someone already has access to the right files. It takes much longer if the business has split records across multiple inboxes and folders.
Keep the names, phone numbers, and email addresses of everyone involved in the response. That includes staff, outsourced IT, the insurer, solicitors, and any specialist provider.
If the claim may involve personal data, record any notices sent to affected people or regulators. If a third party was affected, keep those messages too.
If the incident touched payment data or customer communications, keep a note of any reference to the Financial Conduct Authority, Privacy and Electronic Communications Regulations, or sector rules that came up during the response.
Proof of cost and loss to keep
Save every bill linked to the incident, even if the amount looks small. Small emergency costs often get overlooked, then become hard to prove later.
That includes courier charges, replacement kit, overtime, temporary staff, external support, and any restoration work. A claim file without cost proof tends to grow weak very quickly.
One practical habit helps a lot: keep a running spreadsheet or note with date, supplier, reason, and amount. It sounds boring. It saves hours later.
A good claim pack tells one clear story: what happened, what it cost, and why the cost follows from the incident.
The strongest claims files are built around a simple set of records. Businesses should keep the incident notice, screenshots, access logs, emails, ransom notes if relevant, invoices for emergency support, and a running note of every call with the insurer, suppliers and advisers. Contact details for the claims handler, incident response provider, IT team, solicitor, and any forensic firm should sit in the same folder as the evidence.
In a business interruption claim, the finance pack matters as much as the technical material, so sales records, downtime notes and proof of restoration costs should be saved together. Good evidence gathering shortens the claim timeline because the insurer can check the facts without repeated follow-up.
What slows or derails a claim
Late notice, weak evidence, and unauthorised changes cause most avoidable delays. Those three problems show up far more often than owners expect.
Late notice and missing evidence
Late notice can create coverage questions even when the loss is real. Missing evidence can do the same.
The error most frequent here is thinking that a verbal call is enough. It is not. The insurer still needs the chain of events, and that chain is built from records.
A claim can also slow down when the business cannot show when the incident started. Without that starting point, timing-based cover becomes harder to assess.
Unapproved repairs and broken chain
If staff or suppliers change systems before approval, the claims handler may lose the clean trail needed for investigation. That is not a small issue. It can change the shape of the claim.
This is also where forensics gets messy. If evidence is touched too early, the specialist may not be able to tell what the attacker changed and what the business changed later.
The fastest route is usually the correct one only if the insurer has already agreed it. Otherwise, speed can cost time.
Policy gaps you must check
Check exclusions, waiting periods, cover limits, and the excess before you submit the claim. These decide how far the insurer can go.
The UK government’s guidance on cyber incidents and the NCSC’s advice both point towards the same habit: preserve evidence, report early, and keep a clear record of action. UK government cyber security guidance
If the claim also includes third-party liability, the insurer may need to separate your own loss from another business’s loss. That is another common place where timing stretches.
What changes in data breach and ransomware cases
Ransomware and data breach claims usually need more people and more proof. That is why they run longer than simple repair claims.
When legal advice becomes essential
Legal advice becomes essential when the incident may trigger notification, extortion, contract, or liability issues. The claims handler may want legal sign-off before any external communication goes out.
For a data breach, that can mean checking the UK GDPR and Data Protection Act 2018 duties before customer emails are sent. It can also mean checking whether the breach is reportable to the ICO.
For ransomware, legal input often matters before any payment discussion, because the insurer needs to consider security, sanctions, and recovery risks.
When third parties must be told
Third parties may need to be told if their data, systems, or contracts were affected. That can include clients, suppliers, payment providers, or service platforms.
This is where the claim often slows down quietly. The insurer may wait while the business works out who must be informed and what can be said safely.
If the issue spreads into customer service or outsourced systems, third-party liability can sit beside the main claim. That doubles the paperwork very quickly.
When the claim becomes multi-track
A multi-track claim has several moving parts at once. IT recovery runs alongside legal review, finance evidence, customer communication, and insurer approval.
That is normal in serious incidents. It is also the reason owners should not expect one neat answer on day one.
A claim that looks straightforward at first can still become complex once exclusions, third-party issues, or waiting periods are involved. What looks like a single event can become three linked files: restore the system, prove the loss, and handle the legal side. Each one takes its own time.
The best recommendation is simple: notify fast, preserve everything, and wait for the claims handler before major repairs. That works well in most cases, but only if the policy actually covers the event and the business can prove a financial loss. If the incident is outside cover, the same speed will not change the outcome. If the loss is covered, clean records usually shorten the claim by days or even weeks.
This process does not work the same way if the incident is clearly outside the policy, if there is no financial loss to show, or if the business is comparing insurers rather than filing a live claim. In those cases, the right next step is a policy review, not a claim submission.
Frequently asked questions
How long does a cyber claim usually take in
Most take from a few days to several weeks. Minor incidents can close fast if the evidence is clean, while ransomware, data breach, and business interruption usually take longer because forensics, legal review, and proof of loss slow the process.
What should a small business send the insurer
The first pack should include the incident time, a short description, screenshots, logs, and who is already involved. Add any ransom note, breach alert, invoice, or downtime proof. The cleaner the first email, the less chasing later in the claims timeline.
Does telling the insurer late affect cover?
Yes, it can. Many policies expect notice as soon as possible, and late notice can create coverage arguments or delay approval. The issue is not only speed. It is whether the insurer can still trust the timeline and preserve evidence properly.
Why do ransomware claims take longer than other
Ransomware claims often need forensics, legal input, and careful recovery planning. They may also involve extortion decisions and possible system rebuilding. That means the claims handler cannot usually approve everything at once.
What is the waiting period for cyber business
It is the time before BI cover starts to pay after an outage begins. If the outage ends before that period ends, there may be no payment. This is why the waiting period can matter more than the technical fix itself.
If personal data is involved, the answer can be yes. Under UK GDPR, the usual rule is to report certain breaches within 72 hours where feasible. The insurer may also want to review the wording before anything is sent.
Can a claim be approved before all costs are
Yes, sometimes. The insurer may approve emergency steps first, then review the wider loss later. That happens most often when the incident is urgent but the full business interruption loss is still being calculated.
Claims close faster when the file stays clean
The claim closes faster when the facts stay simple, the evidence stays intact, and the insurer gets updates early. That is the pattern.
The practical lesson is plain. Notify quickly, keep records, avoid unauthorised fixes, and separate technical recovery from financial proof. SMEs that do those four things usually shorten the process more than any other single action.
If the insurer can see the event, the cover, and the loss in one clean trail, the claim usually moves much faster.