Authors
Commercial disputes and insurance recovery partner Eleanor Ruiz was joined by Mark Jennings from forensic accounting firm BRG and Elsa Ramirez from insurance broker Willis Towers Watson. The three colleagues gathered for a panel discussion at London International Disputes Week 2026 to explore how to react to a cyberattack and prepare ahead for potential disputes down the line.
The likelihood that a business will suffer a cyberattack at some point feels almost inevitable. We know that those attacks can be extremely costly, lock companies out of their own systems for weeks, and send shock waves through boardrooms and the wider industry. Well-run companies that simply are not ready may be brought to the brink of insolvency.
The difference between organisations that recover and those that do not comes down to preparation, and that preparation begins at the board level.
The first 72 hours
The moment a cyberattack is identified, multiple clocks begin ticking simultaneously, and it is this convergence of deadlines that can create an initial sense of panic.
You have 72 hours to notify the Information Commissioner’s Office (ICO) under UK GDPR. The ICO's 72-hour window starts from the point of “awareness”, which is a legally contested concept. When was the alert first flagged? When did it reach your data protection officer? When did it reach the board? All of these distinctions matter for future disputes and policy coverage, and documenting them carefully is essential.
Legal privilege is critical from the outset. If you commission a forensic investigation report without the protection of legal professional privilege, the findings can become disclosable. That means your own report can be used against you by your regulator or a third-party claimant.
Consider what people might say on Teams or WhatsApp in those first 72 hours. Messages like “we’ve known about that for ages” or “we were planning to roll out multifactor authentication but never got around to it” might be disclosable down the line and might become an incredibly difficult narrative to overcome.
Another increasingly relevant concern is the use of artificial intelligence or deepfakes as part of these attacks. Threat actors can use AI-generated content to impersonate senior executives, authorise payments, or misdirect a response once the attack has happened. This makes it enormously difficult to identify what was real in the first place and whether reliance on any particular communication was reasonable.
Notify insurers
In the event of a cyberattack, insurance notification should happen as soon as possible. If it is a ransom demand or if your systems are down, call the insurance hotline immediately. This allows IT forensics to be instructed through the proper vendor channels.
Broker collaboration is crucial because some policy wording allows nil retention for the first 72 hours, meaning that all costs in the initial window are absorbed by insurers. Think of insurers as your partners. They handle incidents day in and day out, and they have valuable insights into threat actor activity and response mechanics.
It is also essential to submit the vendors’ scope of work and budgets to insurers early and to get approvals upfront. If you wait three or six months and present your costs after you have already incurred them, insurers are significantly more likely to challenge them, questioning the suitability or competence of the appointed vendor or arguing that the costs were excessive.
When a cyber incident occurs, it is worth pulling out every insurance policy you hold – not just the stand-alone cyber cover. Combined risk policies and professional indemnity policies may also respond. If multiple policies each contain an “other insurances” clause, those clauses may cancel each other out (depending on the exact language used), in which case the policyholder could be entitled to claim against any policy in the order of their choosing.
Understand where the real costs sit and how your policy responds
The immediately visible costs, such as forensic IT, legal, PR, and system rebuild costs, can accumulate quickly. Under a typical cyber policy, these are categorised as incident response and system restoration costs and can be undertaken by pre-approved panel vendors or your preferred vendors with the insurers’ consent.
After those costs, you’ll have data restoration and data recovery costs, which can be a significant line item. If your backups were not actually in place at the time of the incident (even if the lack of backups had nothing to do with the attack itself), insurers may challenge coverage, depending on whether the backup arrangements align with the representation made at policy inception.
But the main financial impact often crystallises in the disruption to the business: lost income during downtime, continuing business interruption as the business recovers, and extra expenses incurred to mitigate those losses.
Two key policy parameters to understand are:
- The waiting period (currently 8 to 12 hours in the market, though some clients have up to 24 hours).
- The maximum indemnity period (typically 180 days, though some brokers are now pushing for 365 days). If your losses extend beyond the maximum indemnity period, as they often do, the policy simply will not respond to those ongoing losses.
Setting the maximum indemnity period is critical. This time frame must provide sufficient runway for the business to recover economically after technical restoration of the systems. These two points rarely coincide: in many cases, it is only after the systems are back online that the true recovery process can begin. Take, for example, a manufacturing company. It may suffer only a couple weeks of downtime, but the financial impact can extend much further: additional costs to make up lost production, ongoing production inefficiencies, cancelled orders, lost customer contracts, and other losses that persist beyond the restoration period.
The scale of these sums cannot be underestimated. Even the biggest businesses can find themselves on the brink of insolvency. Nonetheless, insurers are there to support you through difficult times. Therefore, early and open communication with both your broker and insurers is essential. If the incident has created financial difficulty, it is important to clearly explain the challenges you are facing, the impact on cashflow, and any critical timelines by which funding may be required. It is in everyone’s interest to work collaboratively, and, where appropriate, brokers can work with insurers and policyholders to help facilitate interim payments and provide financial support during the recovery process.
The areas that most commonly give rise to coverage disputes
- Betterment. There is a betterment exclusion in most cyber policies; the policy is designed to return you to where you were before the attack, not to fund an upgrade. When rebuilding systems, you must demonstrate to insurers that the work is remediation, not improvement. Similarly, hardware replacement is only covered where there is a demonstrable reason the existing hardware can no longer be used as a direct result of the attack.
- Multifactor authentication. One of the biggest coverage battlegrounds in recent times has been multifactor authentication (MFA). Where MFA was not in place at the time of an incident, insurers have relied on the Insurance Act to change the terms of coverage, arguing that had they known MFA was absent, they would not have underwritten the risk in the same way. The proposal form is not a sales document. It must be an accurate reflection of your security posture – good or bad.
- Ransom payments. If a ransom payment is considered, it is important to engage with insurers. While the decision to pay a ransom ultimately rests with the business, insurers will expect to understand the rationale for the payment and whether it represents a reasonable course of action in the circumstances. This may include situations where no viable backups are available, where a decryption key is required to restore critical systems, or where a payment is considered necessary to reduce the risk of sensitive data being published. As with all decisions taken during an incident, insurers will expect you to act as a prudent uninsured. Of utmost importance, sanctions checks must be completed by both the ransom negotiator and the insurer. The ransom negotiator will typically issue a certificate confirming that the threat actor is not a sanctioned entity, while the insurer will conduct its own sanctions assessment before authorising any payment.
- War and terrorism exclusions. Despite very real difficulties in identifying who is responsible for or supporting an attack, war and terrorism exclusions are increasingly relevant in the context of state-sponsored or state-affiliated threat actors.
- Retroactive dates. Whilst we do see retroactive date provisions in some policies, our expectation would be that full retroactive cover applies, as this remains the market standard.
Prepare before anything goes wrong
The organisations that will fare best in the aftermath of a cyberattack are those that treat documentation as a discipline – not as an afterthought.
The best time to prepare is vastly in advance of any incident. Preparation is one of the variables you can control. Consider the following preparations:
- Know how you will capture operational data as it comes in, including customer service call notes, order cancellations and delays, order backlogs, lost contracts, and operational records. When you come back six or 12 months later looking to present a claim to insurers or to pursue a recovery action, you will need data to support it.
- Be clear as to how you would justify a business interruption claim. It is significantly easier to do so where operational evidence shows the impact of the cyber event, and the financial evidence then puts a value on that impact.
- Review your infrastructure regularly. Ensure that what you actually have in place matches what you have told your insurers on your policy proposal form. If you have a gap, either close it or disclose it. Keep updating proposal forms when something material changes, such as new vendors, new systems, and changes to backup architecture. After an incident, a forensic report will be produced and assessed by insurers, and you do not want them to find discrepancies.
- Run tabletop exercises. Involve your information technology team, legal team, and the board, because in those first 72 hours, decisions are being made by very senior people who may not have had direct experience with incident preparation. These scenarios should be run to reflect reality, where incidents unfold over a number of days and weeks, with incomplete information and shifting circumstances.
- Keep critical contact numbers accessible offline. When everything shuts down, you need access to the insurance hotline. Key contact information should be printed out and stored somewhere safe and accessible – even if it needs to be accessed at 2 a.m.
What to remember
A cyberattack is a boardroom literacy problem as much as it is a legal one. Get the CEO, CFO, and GC into a room with IT and your insurance team to walk through a cyber incident response plan and the associated insurance cover, line by line. Make sure that everyone is clear who owns what responsibilities and where the hotline numbers are stored.
Companies that survive are those that treat a cyberattack as potential dispute territory from the very first moment with a focus on preserving privilege, notifying insurers, documenting rigorously, and preparing honestly.
Client Alert 2026-176