Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

When should you contact cyber insurance?

Updated

Notify the cyber insurer as soon as the incident is a possible claim — often before you pick DFIR or outside counsel. Read YOUR policy's notice and panel-vendor clauses. This page is not legal advice and not coverage advice.

Operational guidance, last verified 7 September 2026 against NAIC cyber-insurance consumer guidance (with the FTC), NAIC Receivership and Insolvency Task Force materials on cyber claims, CISA's #StopRansomware Guide, the FTC Data Breach Response guide, and NIST SP 800-61r2. It does not interpret your contract, does not rank carriers, and is not a substitute for counsel, your insurer, or a retained DFIR firm. Verify YOUR policy.

Notify before you pick a panel vendor

Audience: a founder, CTO, CISO, or incident commander who has a cyber policy and is mid-incident. The who-to-call page on this site is the contact map. This page is the insurance-notice step on that map: when to call the carrier, why the call often comes before you retain DFIR or outside counsel, and what they will ask. The contact-breach-counsel page on this site is the privilege-and-engagement checklist. The what-is-dfir page on this site is the DFIR explainer. A dedicated 'when you need DFIR' guide is not on this site yet; until it is, that role stays in prose.

The operational rule is: notice the insurer before you engage panel vendors. Many cyber policies treat prompt notice as a condition of coverage, and many require you to use a pre-approved panel for forensics, counsel, notification, and crisis communications — or to get written consent before you retain anyone else. NAIC Receivership and Insolvency Task Force materials on cyber claims record that some policies require a preapproved incident-response vendor list, and others require prior mutual agreement before a particular provider is retained. That is a description of common policy design, not a reading of YOUR form. Last verified 7 September 2026. Not legal advice. Not coverage advice.

  • Find the policy (or the broker's claims packet) and the 24/7 breach hotline. The NAIC/FTC cyber-insurance consumer flyer tells buyers to ask whether the carrier offers a breach hotline available every day of the year at all times. Use the number on YOUR documents, not a number from a search result.
  • Call as soon as the incident is a possible claim — in the first hour if that is what the notice clause says, not after you 'know everything'. Waiting for a complete forensic picture is how late-notice arguments start.
  • Do not retain a DFIR firm, restorer, or outside counsel off the panel until you have asked the carrier (or the broker) which vendors the policy recognises. If a vendor is already on a retainer your policy pre-cleared, say so. The contact-breach-counsel page on this site is the privilege-and-engagement checklist. The what-is-dfir page on this site is the DFIR explainer. A dedicated 'when you need DFIR' guide is not on this site yet.
  • Do not reimage, delete logs, or 'clean up' so the claim looks tidy. The FTC Data Breach Response guide is explicit: do not destroy forensic evidence during investigation and remediation. NIST SP 800-61r2's evidence-handling guidance is acquire, preserve, secure, and document. The first-24-hours page on this site is the hold checklist.
  • Read YOUR policy. This page does not interpret it, does not bind a carrier, and does not rank carriers.

Generic policy-condition concepts — verify against YOUR policy

Cyber policies are contracts. The conditions below show up often enough that NAIC materials and incident-response practice treat them as expected questions. They are not a statute, not a model form, and not YOUR coverage. Some policies are stricter; some are quieter. Confirm each row against the form you actually bought, including endorsements and the panel list. Last verified 7 September 2026. Not legal advice. Not coverage advice.

Common cyber-policy conditions (generic; confirm against YOUR form — not coverage advice)
Condition (generic name)What it usually asks of youWhat this page is not saying
Prompt notice / notice as soon as practicableTell the insurer about an incident, claim, or circumstance that may give rise to a claim, within the time the form names — sometimes hours from discovery, sometimes 'as soon as practicable', sometimes in writing to a named address or hotline.This page does not start YOUR notice clock and does not decide whether a fact pattern is a 'claim' or a 'circumstance' under YOUR form.
Panel / pre-approved vendorsUse the carrier's list for DFIR, breach counsel, notification vendors, and crisis communications, or get prior written agreement to someone else. NAIC cyber-claims materials: some policies require a preapproved list; others require prior mutual agreement to a particular provider.This page does not name, endorse, or rank any carrier or panel firm. 'Panel' is a contract role, not a quality ranking.
Consent before incurring costsGet the insurer's consent before you retain a non-panel vendor, pay a ransom or extortion demand, or commit to a large restorer. The NAIC/FTC flyer lists forensic services, legal counsel, customer notification, crisis management, and cyber extortion among typical first-party coverages — those are the spend categories the consent clause often sits on.This page is not ransom advice and not a recommendation to pay or not pay. Consent is a coverage question on YOUR form; legality of a payment is a counsel question on YOUR facts.
CooperationGive the insurer the facts it needs to handle the claim: timeline, scope, invoices, and access to the people who know. One internal owner for carrier questions (usually the commander or in-house legal) so two stories do not get told.Cooperation is not a reason to tip the actor on an in-band channel. CISA: do not tip the actor. Keep the out-of-band bridge. Whether sharing with the insurer affects attorney-client privilege is a legal question for counsel, not this page.
Proof of loss / documentationA written account of what happened, what it cost, and why the cost was necessary, on the timetable the form names. The UTC timeline and evidence-hold list on the first-24-hours page on this site are the operational raw material.A reconstructed narrative written next week is a different document from contemporaneous notes. This page does not complete a proof of loss for you.
Duty to mitigateTake reasonable steps to stop the bleeding — isolate, preserve, contain. NIST SP 800-61r2 and the SANS PICERL model put evidence preservation before eradication. Mitigation is not 'rebuild everything tonight'.Mitigation is not a licence to destroy the evidence the carrier, DFIR, and later counsel will ask for. The FTC guide: do not destroy forensic evidence during investigation and remediation.

What the insurer will ask — a checklist

Have this packet ready when you call the hotline or the broker. You will not have complete answers in the first hour. Incomplete-and-honest beats late-and-polished. This is an operational intake list distilled from what NAIC/FTC consumer guidance says first-party coverage typically pays for (forensics, counsel, notification, interruption, extortion) and from what CISA tells operators to track in the first response. It is not YOUR carrier's claim form.

  • Named insured, policy number, broker, and the 24/7 breach-hotline number on YOUR documents.
  • When you first became aware, in UTC, and how (alert, customer, law enforcement, employee). Discovery is often when a notice clause starts — this page does not decide that for you.
  • What you observed: systems, accounts, identity plane, backups, a ransom note if one exists. Unknowns belong on the list, not in a guess.
  • Whether personal data, payment data, or a regulated dataset might be involved. 'Might' is enough to flag; whether a notification duty has started is counsel's question.
  • What you have already done: isolation, evidence hold, who you called, whether anyone reimaged or deleted logs. The first-24-hours page on this site is the hold-and-timeline checklist.
  • Whether you have already retained counsel, DFIR, a restorer, or a notification vendor — names, when, and whether you believe they sit on the panel. If you have not retained anyone, say that. The contact-breach-counsel page on this site is the privilege-and-engagement checklist. The what-is-dfir page on this site is the DFIR explainer. A dedicated 'when you need DFIR' guide is not on this site yet.
  • A single point of contact who will answer follow-ups (commander or in-house legal), on the out-of-band channel. NIST SP 800-61r2: designated people, not a blast.
  • Whether a ransom or extortion demand is in play, and whether anyone has already paid or promised to. Do not negotiate on a channel the actor can see. This page is not ransom advice.

Insurer notice is not a regulator filing

Mixing these is how a coverage call turns into fake legal advice. Noticing your cyber carrier is a contract step. Reporting to CISA, the FBI, a state attorney general, a data-protection authority, or a sector regulator is a different kind of act — sometimes a legal duty, sometimes voluntary sharing. One does not discharge the other. Last verified 7 September 2026. Not legal advice.

CISA's #StopRansomware Guide tells operators to follow the notification requirements in their own incident-response plan and lists 'cyber insurance company' among the relevant stakeholders, next to IT, managed security providers, and leadership. The same guide's contact table has a Cyber Insurance row. That is operational handling advice from CISA, not a statute, and not a statement that a CISA report satisfies a policy notice clause — or the other way around.

The FTC Data Breach Response guide, which is US regulator guidance for businesses rather than a statute, tells firms to assemble a team that can include legal, forensics, information security, operations, communications, and management, and not to destroy forensic evidence. It does not tell you how to notice a carrier. The team list and the evidence hold still apply while you are on the phone with the insurer.

Do not mix policyholder notice with insurance-licensee notice. The NAIC Insurance Data Security Model Law (#668) is about insurance licensees notifying a state insurance commissioner of a cybersecurity event. It is not the clause in YOUR cyber policy, and it does not apply to you merely because you bought a policy. Counsel maps YOUR duties. Mapping is not filing.

Three different notices (described as published; not a determination; not legal advice)
KindWhat it isSource, and the limit
Policy notice (contract)Telling YOUR cyber insurer about an incident or claim, on the timetable and channel the form names, often before you pick a panel vendor.YOUR policy. NAIC/FTC consumer flyer (what coverage typically includes; ask about a 24/7 hotline). NAIC cyber-claims materials (panel / prior-agreement vendors). This page does not interpret the form.
Operational sharing (advisory unless a duty applies)CISA asks organizations to report cyber incidents; the #StopRansomware Guide lists the cyber insurance company as a response stakeholder. FBI IC3 is a complaint intake.CISA #StopRansomware Guide; CISA reporting pages. Sharing with CISA is not a policy notice and not a GDPR, CRA, or US-state filing. Last verified 7 September 2026, CIRCIA mandatory reporting is not in effect.
Legal notification (only if it applies)US state (and territory) breach-notification statutes; sector rules such as HIPAA; GDPR Article 33; CRA Article 14. NAIC Model #668 commissioner notice — for insurance licensees, not for every policyholder.The statute or regulation itself. The first-24-hours page on this site maps clocks that MAY apply; it does not start one. Counsel maps YOUR facts.

Coverage pitfalls — common, not a ranking of denials

These are the ways a mid-incident team talks itself out of the call, or makes the call too late to use the panel. They are operational failure modes, not a prediction that YOUR claim will be denied, and not a ranking of carriers. Verify YOUR policy. Not coverage advice. Not legal advice.

  • Waiting to 'know everything'. Notice clauses often run from discovery of an incident or circumstance, not from a finished forensic report. Incomplete-and-on-time is the job in the first hour.
  • Hiring a favourite DFIR firm or law firm first, then telling the carrier. If the form requires the panel or prior consent, a unilateral engagement is a coverage argument you do not want. Ask first. The contact-breach-counsel page on this site is the privilege-and-engagement checklist. The what-is-dfir page on this site is the DFIR explainer. A dedicated 'when you need DFIR' guide is not on this site yet.
  • Skipping notice to 'preserve privilege'. Common practice is that counsel directs DFIR so working papers can sit under attorney-client privilege — that is practice, not a ruling that privilege will attach on your facts, and not a reason to miss a notice clause. Privilege is a legal question for counsel. Coverage is a contract question on YOUR form.
  • Reimaging or deleting logs so the environment 'looks contained' before the carrier or DFIR sees it. FTC: do not destroy forensic evidence. NIST SP 800-61r2: preserve, then eradicate.
  • Treating a CISA report, an IC3 complaint, or a customer email as if it noticed the insurer. It did not. The hotline and the address on YOUR policy are the notice channel unless the form says otherwise.
  • Negotiating a ransom or promising a payment without asking whether the form requires consent. The NAIC/FTC flyer lists cyber extortion among typical first-party coverages; consent, legality, and whether to pay are not this page's job.
  • Naming two owners for the carrier. Split instructions are how two scopes, two vendor retainers, and two stories get born. One commander, one carrier contact.

Where this shows up in ShipReady Metrics

The signed-in app does not notice an insurer, interpret a policy, retain a panel vendor, or file a claim. It does not keep a copy of your policy. If you already have a session: signed-in app → Compliance → CRA reporting tracks the 24-hour / 72-hour / 14-day ladder from your recorded awareness for findings the org has classified as CRA-in-scope. That ladder is not an insurer notice, it does not start a clock for you, and it is not a determination that CRA applies. A named human still submits. None of those surfaces is a substitute for the commander, counsel, the insurer, or DFIR.

Primary sources (last verified 7 September 2026)

Every operational and regulatory claim on this page is taken from one of these. If a later revision of a source changes the advice, the date above is how you can see we have not re-checked yet.

The NAIC/FTC 'Cyber Insurance' consumer flyer is guidance for buyers on what first-party and third-party cyber coverage typically includes (forensics, legal counsel, notification, interruption, extortion, a 24/7 breach hotline) — it is not a policy form and not coverage advice on YOUR contract. NAIC Receivership and Insolvency Task Force cyber-claims materials describe panel-vendor and prior-agreement conditions as they appear in policies; they do not interpret YOUR policy. NAIC Insurance Data Security Model Law (#668) governs insurance-licensee notice to a state insurance commissioner, not policyholder notice to a cyber carrier. CISA's #StopRansomware Guide lists the cyber insurance company as a response stakeholder. The FTC Data Breach Response guide is business guidance from a US regulator; do not destroy forensic evidence. NIST SP 800-61 Revision 2 remains the current final Computer Security Incident Handling Guide (August 2012) — guidance, not a statute.

Frequently asked questions

When should we contact cyber insurance after a breach?

As soon as the incident is a possible claim — often in the first hour, and before you pick a DFIR firm or outside counsel off a panel. Read YOUR policy's notice clause and the panel list. The NAIC/FTC flyer tells buyers to ask about a 24/7 breach hotline; CISA's #StopRansomware Guide lists the cyber insurance company as a response stakeholder. This page does not interpret your contract. Not legal advice. Not coverage advice.

Can we hire our own DFIR firm or lawyer before we call the insurer?

Ask the carrier first if the form requires a panel or prior consent. NAIC cyber-claims materials: some policies require a preapproved incident-response vendor list; others require prior mutual agreement to a particular provider. A unilateral engagement is a coverage argument. The contact-breach-counsel page on this site is the privilege-and-engagement checklist. The what-is-dfir page on this site is the DFIR explainer. A dedicated 'when you need DFIR' guide is not on this site yet. Counsel-first for privilege is common practice, not a reason to skip notice. Not legal advice. Not coverage advice.

What will the cyber insurer ask for?

Typically: named insured and policy number, when you became aware, what you observed, whether personal data or a ransom demand is in play, what you have already done (isolation, evidence hold, who you called), whether anyone is already retained, and a single point of contact. Incomplete-and-honest beats late. The first-24-hours page on this site is the timeline and hold checklist. This is an operational intake list, not YOUR claim form.

Does notifying the insurer satisfy CISA, FTC, or regulator notice?

No. Policy notice is a contract step. CISA reporting is operational sharing for most operators today; last verified 7 September 2026, CIRCIA mandatory reporting is not in effect. Regulator filings (US state statutes, HIPAA, GDPR Article 33, CRA Article 14, NAIC Model #668 for insurance licensees) are legal requirements only when they apply. One does not discharge another. Counsel maps YOUR facts. Not legal advice.

Is this legal or coverage advice?

No. It is operational guidance distilled from NAIC cyber-insurance consumer guidance, NAIC cyber-claims materials on panel vendors, CISA's #StopRansomware Guide, the FTC Data Breach Response guide, and NIST SP 800-61r2. Whether a notice clause is satisfied, whether a panel condition applies, whether privilege attaches, and whether a regulator filing is due are questions for counsel and YOUR policy. This page does not rank carriers and does not interpret your contract.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.