A cyber coverage dispute is not decided in the room where the parties finally sit down to argue about it. It is decided months earlier, in the first hours after the incident, by people who are not thinking about coverage at all: the security engineer drafting an email to the incident-response vendor, the assistant adding names to a distribution list, the forensic analyst deciding how to frame a preliminary finding. By the time counsel is retained for the coverage fight itself, that record already exists, for better or worse.
The pattern repeats across three points of failure. A forensic report circulated the way IT teams circulate things becomes the central exhibit in a privilege fight nobody planned for. A remediation vendor chosen for speed, without checking the policy’s panel requirement, becomes a line item the insurer disputes rather than pays. A loss narrative built around the story of what happened, not the categories the policy pays under, has to be re-cut under deadline once the proof of loss is due. None of these are coverage failures in the ordinary sense — the policy may well have responded. They are record failures.
The fix is a different discipline, applied by people managing an active incident who are not thinking about coverage — so it has to be built into the response protocol in advance, not improvised later. For the mediator who eventually gets the dispute, the same record sets the terms of the session: it decides what can be established, what cannot, and where the gap has to be closed before a number gets discussed.
§ 01 · Why the forensic report becomes the fight
Start with the document that causes the most damage after the fact: the forensic report, which insurers and opposing parties both want because it is the most candid account of what happened. Whether it is protected from disclosure turns not on what the report says but on how it was created and handled — forensic reports lose privilege protection when treated as ordinary business documents rather than as legal work product, typically where the report is widely circulated internally, used beyond the investigation, or the forensic firm’s engagement predates any real litigation concern. That is paperwork discipline, decided in the first days by whoever set up the engagement letter and the distribution list.
A recent legal update on cyber-incident response practice makes the underlying problem plain: in the middle of an active incident, “deciding whether to put certain details in writing—and whom to include on communications—may not be top of mind.” That is exactly the point at which the record either survives later scrutiny or does not.
§ 02 · The Move: run the investigation the way privilege requires
Build privilege into the investigation from its first meeting, not into the report after it is written. Put that discipline in place the moment outside counsel or a forensic vendor is engaged in response to a suspected intrusion, before a single finding is documented — waiting until the report is drafted to think about privilege is waiting until after the exposure has already been created.
Execute it with four habits: include attorneys in incident-response meetings so that “sensitive, deliberative conversations are informed by legal advice and remain privileged”; share information “strictly on a need-to-know basis to avoid waiving privilege”; periodically “review distribution lists to confirm that emails about the incident are not distributed to unintended recipients”; and keep substantive analysis off ordinary email — “sharing communications regarding potential findings, conclusions, observations, recommendations, or concerns … should generally occur orally … with legal counsel present” — with any writing that must occur routed through counsel and marked privileged and confidential.
§ 03 · The Move: lock the vendor and endorsement chain before the incident
Resolve which forensic and remediation vendors the policy allows before any incident, not while the response clock is running. Settle it at renewal: vendor selection made under pressure is where coverage gets contested later.
Cyber policies commonly steer the insured toward a panel of pre-vetted vendors, and paying an unapproved vendor is a frequent source of dispute. Companies “should ensure they are comfortable using the vendors on the insurer’s panel or obtain an alternate policy that allows selection of independent vendors,” and where they want to keep their own vendor, “should still seek pre-approval of their preferred vendors by endorsement onto the policy to ensure there is no dispute in the critical hours following discovery of a cyber incident.” The same discipline extends to the programme as a whole: a cyber event increasingly triggers D&O exposure too, so review both policies together and negotiate carve-outs for the whistleblower, privacy, and data-breach claims a broad cyber exclusion can otherwise sweep in.
§ 04 · Documenting the claim as the incident unfolds
Once the incident is underway, the habits shift from privilege to proof. A cyber claim is a proof-of-loss exercise, built in real time because it cannot be reconstructed convincingly afterward. Get the application right before any incident, since “an inadvertent error in completing the application may be used as a basis to deny coverage,” and report immediately: “most cyber policies require immediate (or close to immediate) reporting,” with a late notice standing as an independent ground for denial.
Keep a real-time recovery narrative rather than reconstructing one later, tracking “impacted systems, dates of partial and full restoration, details about interruptions to operations and revenue,” alongside a “detailed description of the loss (including time, place and cause) and a calculation of losses.” Keep “detailed statements of work and detailed records of work performed” for every vendor, and separate costs that restore the prior environment from costs that upgrade it, since insurers decline to pay for bundled enhancements. Correct a reservation-of-rights letter’s factual errors in writing immediately, or the error becomes the insurer’s account by default. These habits let counsel “identify, quantify and maximize” the loss as it happens, not reassemble it from memory later.
§ 05 · What a disciplined record gives the neutral
This is also where a coverage mediation gets structured. Cyber coverage disputes suit mediation and arbitration because they braid technical fact questions into insurance-law questions, and a neutral needs fluency in both — as I’ve written elsewhere, the right mediator is one who understands “insurance, the law and the underlying technical systems at play in a given cyber insurance dispute.”
The record that decides a coverage dispute is built in the first hours, by people who are not thinking about coverage.
A neutral working from a disciplined record can go straight to what is genuinely contested — whether an exclusion applies, whether a sub-limit was triggered, whether a cost was restoration or enhancement — because the facts are already established, privileged and organized, rather than reconstructed live in the session. A neutral working from an undisciplined one spends the first sessions on forensic archaeology: what the report says, whether it is usable, and what the company’s own emails already gave away.
Build the record for the dispute you hope never to have; if the claim is contested, that record is the only evidence anyone will trust. Waiting for the reservation-of-rights letter to start building it is waiting too long.
Draws on Marcus A. Christian, Adam S. Hickey, Amber C. Thomson & Kathryn Allen, “2024 Cyber Litigation Legal Update – What Your Business Needs To Know,” Mayer Brown (October 11, 2024), for incident-response privilege protocol only; Andrea DeField, Geoffrey B. Fehling, Charlotte E. Leszenske & Lorelie S. Masters, “Reducing Risks from Cyber Incidents with Cyber and D&O Insurance,” Hunton Andrews Kurth (August 3, 2023); Reed Smith LLP, “Cyber coverage: 13 ways to maximize it before and after a breach” (June 6, 2023); and Daniel B. Garrie, “Best Practices: Mediating Cyber Insurance Claim Disputes,” Daily Journal (August 30, 2019; updated May 26, 2020).