
Call your cyber insurer's claims hotline first, before you hire any outside forensics firm or negotiator. These ten questions cover what owners ask when they file a cyber insurance claim: who to call, what to have ready, and what gets claims reduced or denied.
When should we notify our cyber insurer?
As soon as you suspect an incident, not after you've confirmed it. Many policies require notice "as soon as practicable," and Huntington's claims guidance warns that delays "may jeopardize your claim" (Huntington).
Put the claims hotline number in your incident response plan today, not in an email nobody can reach during an outage.
What do we need when we call the claims hotline?
Your policy number, your broker's contact, a short summary of what happened and when you noticed it, which systems or accounts look affected, and one named person who'll be the contact.
You don't need a full report yet. Forensics builds the detailed record later, and that becomes the basis for your proof of loss.
Who do we call first: the insurer, IT or a lawyer?
The insurer's claims hotline. Most policies will connect you with a breach coach, a lawyer who coordinates the response.
Your IT provider should start containment at the same time, such as isolating machines and disabling compromised accounts. Just don't hire outside forensics or negotiators until the carrier approves them.
What is a breach coach?
A breach coach is an outside attorney, usually supplied through your policy, who runs the incident from a legal angle. They direct the investigation, bring in forensics and work out your notification duties to customers and regulators.
The policy usually covers their fees, but those fees typically count toward your retention and use up part of your limit.
Can we use our own IT company or forensics firm?
Sometimes, but check first. Many carriers require pre-approved panel vendors, or reimburse less for anyone else. Huntington advises policyholders to "check with your insurance carrier and breach coach before hiring outside vendors" (Huntington).
Your regular IT provider usually stays involved for containment and recovery. Ask your broker now whether your policy lets you use them.
What should we document during the incident?
Everything, with timestamps. Record when you noticed the problem, who you called and when, which systems were affected, and every decision made.
Keep invoices for overtime and outside help, plus records of lost revenue. Don't wipe or rebuild infected machines before forensics says it's safe, because that evidence supports the claim.
Does a wire fraud loss count as a cyber claim?
Often yes, if your policy includes funds transfer fraud or social engineering coverage. Those are frequently sublimited or sold as add-ons, so check yours.
Email compromise and wire fraud are the most common claims. Coalition reported that business email compromise and funds transfer fraud made up 58% of the incidents it saw in 2025 (Coalition). Our guide to business email compromise covers prevention.
Can money from a fraudulent wire be recovered?
Sometimes, and speed decides it. Coalition clawed back $21.8 million in stolen funds for policyholders in 2025, an average of $202,000 per recovery (Coalition).
Coalition says the sooner you report suspicious activity, the better the odds of getting money back. Call your bank and insurer immediately, then file a report with the FBI at IC3.gov.
Why do cyber insurance claims get denied?
Late notice and hiring vendors without approval are two of the most avoidable reasons. Others are losses the policy doesn't cover and security controls that didn't match what you said on the application.
If you said you had MFA everywhere and the breach came through an account without it, expect a fight. Our guide to cyber insurance requirements covers the application answers carriers check.
Will the insurer pay a ransom?
Some policies cover extortion payments, but the carrier and breach coach control that decision. Most businesses don't end up paying.
Coalition reported that a record 86% of businesses in its ransomware claims refused to pay in 2025 (Coalition). Working backups make refusing possible. See should you pay a ransomware ransom.
Coverage varies by policy. Confirm the details with your broker before you need them.
Discuss cyber insurance readiness for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.



