Skip to main content
Finin2minCurrent Action Guide · 14 Aug 2026
Insurance & PolicyholderUpdated 5 October 2026Checked 14 August 2026

Cyber Insurance Incident Notification: Breach Timeline, Forensics and Claim-Preservation File

By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026

2-minute summary

Current position

The CERT-In Directions of 28 April 2022 remain a current official cyber-incident reporting framework, including the six-hour reporting requirement for reportable incidents. Cyber-insurance coverage, consent requirements, sub-limits and exclusions remain contract-specific and must be checked in parallel.

Control and evidence map

#Control / evidence requirement
1Open an incident chronology at detection time and preserve logs, alerts, affected asset lists and containment decisions.
2Classify whether the incident is reportable to CERT-In or another regulator and route that assessment separately from the insurance claim.
3Notify the insurer/broker through the policy-specified channel and obtain written approval before material external spend where required.
4Maintain vendor scopes, invoices, forensic findings, legal advice and evidence of business interruption or restoration cost by workstream.
5Track recoveries, backups, ransom decisions, third-party claims and sub-limits so the final proof of loss is not a single undifferentiated cyber-cost total.

Worked example

A ransomware incident is detected at 2:00 a.m. The response team preserves logs, isolates systems, evaluates CERT-In reporting, notifies the cyber insurer and confirms the approved forensic vendor before major spend. The finance team then tracks forensics, restoration, legal and interruption costs in separate claim buckets.

Common mistakes

  1. Treating insurer notification as a substitute for CERT-In or sectoral regulatory reporting.
  2. Deleting or overwriting logs during restoration before evidence is preserved.
  3. Hiring expensive incident-response vendors before checking policy consent conditions.
  4. Combining normal IT upgrade spend with incident-recovery cost in the claim.

Frequently asked questions

Does every cyber event have to be reported to CERT-In within six hours?

The Directions apply to reportable cyber incidents within their scope; classify the incident carefully and use the current CERT-In framework.

Should we notify the insurer before we know the full loss?

Usually early notice is safer where the wording requires prompt notice; the quantum can be refined as investigation continues.

Can business-interruption loss be estimated from lost revenue alone?

Not safely. The policy may use defined waiting periods, gross profit or other methodologies and require evidence of causation and saved expenses.

Official sources

Disclaimer: Educational and informational content only. Apply the current law, instrument, policy/contract and facts before acting; obtain professional advice for material or disputed matters.

Disclaimer

Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.

Educational and professional reference only — not financial, tax or legal advice. Verify the current official position from the primary source before relying on any figure, rate, provision or deadline.