Most writing about cyber insurance argues about liability: whether the incident falls inside the policy period, whether an exclusion bites, whether the controls represented at binding were really in place. Those fights are real. But an insured who wins every one of them still has to prove a number, and the number is not argued into existence at the end. It is assembled during the outage, by people whose entire attention is on restoring service.
That is the asymmetry. The carrier will eventually put a forensic accountant on the claim, working with months of hindsight, a defined scope and no systems to bring back up. The insured builds its side of the same record mid-incident, usually with nobody in the room whose job is the claim. Whatever is captured then is what there will be; everything else is reconstruction, and reconstruction is what an opposing accountant is paid to take apart.
The remedy is not more argument. It is a handful of decisions made early, most costing nothing at the time and close to impossible to retrofit.
§ 01 · The clock that matters is not the outage clock
Business-interruption cover does not simply run from the moment systems go down. Many cyber policies impose a temporal deductible first — K&L Gates notes that “some policies only respond once the network has been interrupted for a defined waiting period (e.g., 12 hours).” Below that threshold there is no claim at all, however real the disruption.
So the loss clock and the outage clock are different clocks, and both must be evidenced — to a defensible standard, not from memory. The same source puts the burden plainly: insureds “will need to demonstrate how the loss occurred, including the time of impact and extent of disruption, along with details of any financial losses incurred.” A partial restoration on day three that nobody recorded is, months later, indistinguishable from no restoration at all.
The end of the period is contested as often as the start. In business-interruption terms generally, Hunton Andrews Kurth describes cover as “generally limited to the time reasonably needed to restore operations,” with some policies extending beyond that to “the time needed to ramp up operations to pre-loss levels.” Whether the ramp-up is inside the claim is a policy question; whether the insured can show what it cost is a record-keeping one, and only the second can still be answered a year later.
§ 02 · The Move: keep the recovery narrative in real time
Run a contemporaneous recovery log from the first hour, owned by someone who is not restoring systems, on every incident with plausible BI exposure — and start it before anyone knows whether there will be a claim. The entire value is that it was written while the facts were fresh and nobody was yet arguing about them.
Reed Smith describes the content precisely: “impacted systems, dates of partial and full restoration, details about interruptions to operations and revenue.” That is a log, not a report, and its power is procedural rather than rhetorical. A dated contemporaneous entry is evidence. The same sentence written from memory in month nine is an assertion, and it will be treated as one.
The proof of loss is built on top of it: a “detailed description of the loss (including time, place and cause) and a calculation of losses.” Where exposure is substantial, a forensic accountant prepares that document and argues it against the carrier’s own — their function, in Reed Smith’s words, is to “identify, quantify and maximize these losses.” Retain them early enough to shape what is captured rather than inherit whatever survived, and expect to file more than once: expenses are still running while the claim is prepared.
§ 03 · The Move: segregate restoration from improvement, at invoice level
Split every remediation cost into what restored the prior environment and what improved on it, at the point the invoice is raised — the distinction is nearly impossible to reconstruct from a consolidated vendor bill afterwards.
The reason is structural. Costs that upgrade the environment are commonly excluded, and a remediation invoice that blends the two invites a challenge to the whole line rather than the excluded part of it. The discipline Reed Smith recommends is to require “detailed statements of work and detailed records of work performed” from every vendor engaged — which also makes the accountant’s job possible afterwards.
The carrier’s accountant works with months of hindsight. The insured builds the same record at three in the morning, mid-incident, with no one in the room whose job is the claim.
Vendor choice carries the same trap one step earlier. Many policies, Reed Smith notes, “have pre-approved vendors and counsel that must be used, or require insurer consent before retaining any vendors or counsel.” The forensic firm retained in hour two on the strength of a personal recommendation may be excellent and still produce costs the carrier declines to pay. Equally, carriers often maintain a mitigation protocol, and the advice is to follow it “to avoid the inadvertent destruction or alteration of evidence the carrier may need to investigate the claim.” An insured who wipes and rebuilds fast, sensibly, and without reference to that protocol can destroy the proof of its own loss while doing exactly the right thing operationally.
§ 04 · The exposures that sit outside the obvious claim
Two heads of loss are routinely missed because they do not look like the insured’s own downtime. The first is contingent or dependent business interruption: where the outage stopped the insured performing for someone else, it “may face potential liabilities to third parties, particularly where the outage affected their ability to provide a contracted service.” That is a distinct exposure, usually identified only once a customer’s claim arrives.
The second is the assumption that one policy answers. It does not — “no single insurance policy can or will cover the swarm of difficulties and costs that arise after a large-scale cyber breach.” Cyber, crime, D&O and general liability may each respond to part of the event, and the parts do not align neatly. Reading them together beforehand turns that from a discovery into a plan.
§ 05 · What this changes in the room
A coverage mediation where the insured brings a contemporaneous log, segregated invoices and a proof of loss built on both is a negotiation about policy language. One where it does not is a negotiation about whether the number is believable — and a neutral cannot resolve that by reading the policy, because the dispute has stopped being about the policy. The parties litigate the insured’s own record-keeping instead, a fight nobody priced for and one that cannot be won retrospectively.
Practically, then: (1) start the recovery log in the first hour and give it an owner who is not restoring systems; (2) confirm the waiting period and the definition of the restoration period before you need them; (3) check vendor pre-approval and the carrier’s mitigation protocol before retaining anyone; (4) segregate restoration from improvement at invoice level, not in the reconciliation; (5) retain the forensic accountant early enough to shape capture rather than inherit it; (6) map which of your policies respond to which part of the event; and (7) give notice in writing immediately — most cyber policies require it “as soon as practicable, or within a specified time period,” and in BI terms generally “failure to provide timely notice can jeopardize coverage,” which is the cheapest possible way to lose a good claim.
None of that is a coverage argument. All of it decides how one ends. Build the number while the facts are cheap to record — the day they become expensive is the day you need them.
Draws on Sarah Turpin, “CrowdStrike IT Outage: Wave of Business Interruption Claims Expected,” K&L Gates (July 26, 2024); Reed Smith LLP, “Cyber coverage: 13 ways to maximize it before and after a breach” (June 6, 2023) and “12 essentials you may be surprised to learn about cyber insurance claims” (June 6, 2023); and Hunton Andrews Kurth LLP, “Insurance Coverage for Business Interruption Losses: What Retailers Need to Know” (January 30, 2025), used for the structure of a business-interruption claim generally rather than as cyber-specific guidance. The liability-side counterpart — how the first hours of incident response build the evidentiary record — is treated in № 019.