Cyber Insurance Incident Notification: Breach Timeline, Forensics and Claim-Preservation File
By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026
2-minute summary
- Cyber-insurance preservation starts at incident discovery: record the time, affected systems, containment steps, decision-makers and evidence sources before logs or volatile artefacts disappear.
- Insurance notice and statutory/regulatory cyber reporting are different obligations. Where the CERT-In Directions apply, specified cyber incidents must be reported within the prescribed timeline; the insurer may have a separate immediate-notice and panel-vendor process.
- Before retaining external forensic, legal, ransomware-response or public-relations vendors, check whether the policy requires insurer consent or use of an approved panel. Unapproved spend can create avoidable coverage disputes.
Current position
Control and evidence map
| # | Control / evidence requirement | |
|---|---|---|
| 1 | Open an incident chronology at detection time and preserve logs, alerts, affected asset lists and containment decisions. | |
| 2 | Classify whether the incident is reportable to CERT-In or another regulator and route that assessment separately from the insurance claim. | |
| 3 | Notify the insurer/broker through the policy-specified channel and obtain written approval before material external spend where required. | |
| 4 | Maintain vendor scopes, invoices, forensic findings, legal advice and evidence of business interruption or restoration cost by workstream. | |
| 5 | Track recoveries, backups, ransom decisions, third-party claims and sub-limits so the final proof of loss is not a single undifferentiated cyber-cost total. | |
Worked example
A ransomware incident is detected at 2:00 a.m. The response team preserves logs, isolates systems, evaluates CERT-In reporting, notifies the cyber insurer and confirms the approved forensic vendor before major spend. The finance team then tracks forensics, restoration, legal and interruption costs in separate claim buckets.
Common mistakes
- Treating insurer notification as a substitute for CERT-In or sectoral regulatory reporting.
- Deleting or overwriting logs during restoration before evidence is preserved.
- Hiring expensive incident-response vendors before checking policy consent conditions.
- Combining normal IT upgrade spend with incident-recovery cost in the claim.
Frequently asked questions
Does every cyber event have to be reported to CERT-In within six hours?
The Directions apply to reportable cyber incidents within their scope; classify the incident carefully and use the current CERT-In framework.
Should we notify the insurer before we know the full loss?
Usually early notice is safer where the wording requires prompt notice; the quantum can be refined as investigation continues.
Can business-interruption loss be estimated from lost revenue alone?
Not safely. The policy may use defined waiting periods, gross profit or other methodologies and require evidence of causation and saved expenses.
Official sources
- CERT-In, Ministry of Electronics and Information Technology - Cyber Security Directions under section 70B(6) of the Information Technology Act, 2000 (No. 20(3)/2022-CERT-In; 2022-04-28)
- Insurance Regulatory and Development Authority of India - Master Circular on General Insurance Business (IRDAI/NL/MSTCIR/MISC/90/06/2024; 2024-06-11)
- Insurance Regulatory and Development Authority of India - Master Circular on Protection of Policyholders' interests 2024 (IRDAI/PP&GR/CIR/MISC/117/9/2024; 2024-09-05)
Disclaimer
Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.