Your cyber policy may limit who leads your breach response. This can apply even if you trust a solicitor, IT supplier or crisis adviser.
Appointing an unapproved firm early can leave legal, forensic or PR costs uninsured.
Check panel rules before you buy cover
Check if the policy has a closed, open or hybrid panel. Also check if insurer consent is needed before costs arise.
Is the panel closed, open or hybrid?
A closed panel means the insurer normally chooses response firms. An open panel permits qualified advisers you choose.
A hybrid panel lets you nominate a firm. The insurer must approve it and agree rates.
| Panel model | Who appoints providers? | Likely out-of-panel position | Best fit |
|---|
| Closed | Insurer or breach coach | Usually excluded without consent | SMEs with no existing response advisers |
| Hybrid | Insurer approves your nominee | May be paid at agreed or capped rates | SMEs with trusted advisers |
| Open | Business, within policy terms | Usually covered if qualified and reasonable | Businesses with a tested incident retainer |
When must the insurer approve costs?
The claims condition may require immediate notice through a 24/7 line. It may also require consent before you hire counsel, forensic teams or ransomware negotiators.
Calling a familiar IT contractor first can create uninsured costs.
Know who controls each part of a breach
A breach coach is usually a specialist cyber solicitor. They coordinate the legal response.
They are not your broker, technical investigator or independent coverage lawyer.
What will the breach coach decide?
Panel counsel often assesses legal risk and guides contact with the Information Commissioner's Office. They may also instruct forensic providers.
They advise on whether a personal-data breach triggers the UK GDPR's 72-hour ICO notice rule.
When is separate advice needed?
Coverage counsel advises on the insurance contract. The breach coach manages the insured response.
If cover, exclusions or cost approval are disputed, separate advice can protect the business's position.
Who does what after notification?
Insurer
Approves cover and spend
Breach coach
Coordinates legal response
DFIR firm
Finds and contains intrusion
Broker
Supports communication
Escalate a coverage dispute to independent coverage counsel, not the forensic team.
A cyber insurance panel is a response ecosystem. It is not just a list of solicitors.
When appointing the breach coach, confirm who can instruct each specialist. This includes the forensic provider, PR agency, notification supplier and call-centre provider.
It can also include ransomware negotiators and a forensic accountant. A forensic accountant may help where fraud or business-interruption losses are material.
The legal panel selection should name the lead provider. It should also show the approval route for every specialist.
Response costs can rise fast when suppliers repeat work or act outside scope.
For any panel model, record the rules for out-of-panel advisers. Check whether they need insurer consent and whether their rates are capped.
Also check if the breach coach can make urgent appointments. This matters before a claims handler gives a formal response.
These arrangements also need to account for UK GDPR notification duties. A UK GDPR notice is not just about sending an ICO report within 72 hours. The controller must first assess the risk to people's rights and freedoms.
The controller must keep a record of facts, effects and remedial action. It must update the ICO if the first report is incomplete.
People affected may need notice without undue delay. This applies where the breach is likely to create a high risk.
The notice should use clear language. An applicable exception may remove that duty.
The breach coach can advise on this assessment. The business remains responsible for its decisions.
The business should also check notice duties in its contracts. These may be owed to customers, banks, regulators and key suppliers.
Score and secure your cyber response panel before renewal
Assess providers using evidence and weighted criteria. Give proven cyber skill more weight than a polished sales pitch.
Then agree adviser choice with the insurer. Get written confirmation of approved firms, rates and urgent approval routes before cover starts.
Use a weighted scorecard
Assess England and Wales privacy work, 24/7 access and ransomware skill. Also assess conflict checks, privilege protocols, fees and sector knowledge.
| Check |
Weight |
Evidence to request |
| England and Wales privacy work |
20% |
Named lead and relevant matters |
| 24/7 response and escalation |
15% |
SLA and overnight authority |
| Ransomware and extortion |
15% |
Response process and partners |
Before renewal, give your broker the scorecard. Ask for written insurer confirmation of the agreed arrangement.
Fix hidden cost traps and test notification
Check if legal, forensic, PR, notification and extortion costs share a sub-limit. Also check for lower caps on out-of-panel work.
Check for a separate excess. Ask if reimbursement is limited to panel rates.
Run a 60- to 90-minute tabletop exercise. Use the policy number, notification line and named contacts.
Test authority, escalation and communication between IT, finance, the broker and counsel.
A short test can expose a costly gap.
This is less relevant where a policy permits any qualified provider without prior approval. It also differs where a business has no cyber cover and builds a standalone incident-response retainer. This does not replace advice from a regulated insurance broker or solicitor on a specific policy or live breach.
Questions & answers
Can I use my own solicitor after a cyber breach?
You can use your own solicitor only if the policy permits it. The insurer can also approve them before costs arise.
Ask for written approval, fee terms and cover confirmation. Confirm that their work falls within the relevant legal-cost sub-limit.
What is a breach coach in cyber insurance?
A breach coach is a specialist solicitor who coordinates legal parts of the insured response. They often advise on ICO notice, forensic instructions and customer communications.
They may not handle a cover dispute against the insurer.
Does legal privilege protect every forensic report?
No, legal privilege does not automatically protect every forensic report or internal email. The solicitor should set a written protocol before the investigation starts.
This is especially important where technical findings may later be disclosed.
How quickly should a cyber response firm answer?
A panel firm should offer a 24/7 contact route and respond within 15 to 30 minutes. Check who answers overnight.
Also check if that person can approve urgent forensic containment.
What happens if panel counsel has a conflict?
Panel counsel should check for conflicts before accepting instructions. They should explain any material issue.
If your interests differ from the insurer's, seek independent coverage advice. Notify the insurer through the agreed route.
Make the next renewal decision easier
Use the policy review to record provider choice, approval authority and escalation contacts. Do this before an incident occurs.
The essential points:- A panel clause can be a cover condition, not just a list of suggested suppliers.
- Confirm approval rules and rate caps before hiring your usual lawyer or IT provider.
- Score breach coaches on cyber work, response time, conflicts and privilege process.
- Test the insurer's notification and authority route in a short tabletop exercise.
Learn more
Here are some additional resources on this subject: