Cyber Insurance Claims: What Should SMEs Do After a Cyber Incident?

Your systems are compromised. Your customers want answers. And now you need to make an insurance claim. What comes first?
After a cyber incident, the decisions you make in the first few hours can have consequences long after the immediate threat is contained. Who you call, what evidence you preserve, and when you notify your insurer can all affect the claims process. Here’s a practical step-by-step guide for SMEs in Singapore.
If your SME suffers a cyber incident, contains the threat without destroying evidence, contact your incident-response team, notify your cyber insurer or broker as early as possible, preserve relevant records and avoid making major remediation or ransom-payment decisions without checking your policy.
Your Business Has Suffered a Cyber Incident: What Should You Do First?
- Contain it, but don't destroy evidence. Disconnect affected systems if you need to. Don't wipe or reformat anything yet. A clean reformat also erases the trail your insurer needs to confirm what happened.
- Call your IT or incident response contact. No plans? Get an expert on the phone before you start guessing.
- Notify your insurer or broker early, even with incomplete details. They'll point you to approved forensic and legal vendors.
- Don't pay for a ransom on your own. Ransomware clauses often require insurer sign-off and sanctions of screening first. Paying without checking can cost you coverage.
- Log everything as you go. Screenshots, timestamps, who did what. You'll need this later.
When Should You Notify Your Cyber Insurer?
Immediately, as soon as you suspect something is wrong. Not after you've confirmed the damage.
Cyber insurance notification requirements vary by policy. Some policies may require claims, circumstances or incidents to be reported within specified timeframes, so check your policy wording and notify your insurer or broker promptly.
- Suspicion is enough. You don't need proof, just a reasonable belief that something happened.
- Late notification can complicate a claim, particularly if the delay affects the insurer's ability to investigate or respond to the incident.
- Check your own policy window. They vary. Ask your broker now, not mid-incident.
- Notifying your insurer does not necessarily mean every cost will become a payable claim. Early notification allows the insurer to assess the incident and explain the next steps under your policy.
What Information Should You Preserve?
- Logs. Firewall, server, access logs from around the incident. Don't clear or restart systems before backing these up.
- A forensic image of affected systems, taken before remediation starts.
- Original communication. Ransom notes, phishing emails, attacker correspondence, internal updates. Keep the originals, not summaries.
- A timeline. When it was noticed, who noticed it, what happened next, who was told.
- Invoices. IT, forensics, legal, anything tied to response costs, kept separately.
- A record of exposed data, if any, including how many people are affected.
What Costs May Be Claimable?
Coverage depends on your specific policy, sums insured, and sub-limits, but SME cyber policies in Singapore typically cover:
- Forensic investigation costs to identify and contain the breach
- Legal fees for regulatory and liability advice
- Breach notification costs, including PDPC and affected-individual notifications, sometimes call centre support
- Ransomware and extortion costs, including the ransom itself in some policies, usually with strict conditions
- Business interruption losses from downtime, often after a waiting period
- System restoration, including reasonable security upgrades
- Third-party liability from customers or partners affected by the breach
- PR support, in some policies, for managing reputational fallout
Sub-limits often apply, particularly on ransom payments, so check your schedule rather than assuming the full sum insured applies everywhere.
Mistakes That Could Complicate a Cyber Insurance Claim
- Trying to fix it yourself before notifying. Cost time, evidence, and sometimes your notification window.
- Reformation too early. The single most damaging mistake. Once it's wiped, you usually can't prove how the breach happened.
- Paying a ransom without checking with your insurer. Beyond coverage issues, you risk sanctions exposure if the attacker turns out to be linked to a sanctioned entity.
- Using vendors your insurer hasn't approved. Costs may not be reimbursed at the rate you'd expect, or at all.
- Not reporting smaller incidents. A contained phishing attempt still counts and reporting builds a track record.
- Messy documentation. Gaps and inconsistent accounts slow everything down.
- Not knowing your exclusions. Check exclusions and coverage conditions carefully. Depending on the policy, issues such as security controls, unsupported systems, certain cyber-war events, or other exclusions may affect coverage.
What Happens After You Notify the Insurer?
- Triage. Serious incidents like active ransomware get reviewed within hours.
- Panel vendors deploy. Your insurer may appoint or recommend panel vendors, such as forensic specialists, breach-response counsel and other incident-response providers, subject to your policy terms.
- Investigation and containment. Scope, cause, and ongoing damage control.
- Regulatory guidance. Legal counsel can advise whether the incident meets PDPC notification requirements.
- Cost documentation. Ongoing, not a single lump submission.
- Settlement. Settlement timelines vary depending on the complexity of the incident; the documents required and whether regulatory, legal or third-party issues are involved.
Respond fast to document requests. It's the biggest lever you have over how quickly this move.
How SMEs Can Prepare Before an Incident Happens
- Read your policy now. Know your notification window and any conditions tied to your coverage.
- Save your insurer's claims hotline somewhere you can find it under pressure.
- Write a one-page response plan. Who to call, what to do first, what not to touch.
- Keep declared security controls current. If you tell your insurer, you have MFA and backups, maintain them. A gap here is a common reason claims get scrutinised.
- Review your sum insured yearly. Your data volume and exposure two years ago probably isn't your exposure now.
- Compare policies rather than assume they're similar. Ransomware terms, sub-limits, and panel vendors vary a lot. Worth checking through a broker or aggregator if you don't have someone reviewing this in-house.
A cyber incident is stressful enough without also second-guessing your claim. The businesses that recover with less disruption are usually the ones that notified early, kept their evidence intact, and knew their policy before they needed it.
If you're comparing cyber insurance options or want a second opinion on what your current policy covers, get in touch with us to help you find a plan that fits how your business operates and what's available.
Contact us for policy quotation,
comparison and unbiased advice now!