HIVE80lab — Ops notes

Cyber insurance claim checklist for small teams — the claim is won in the first 48 hours

You bought the policy for the bad day; the claim is decided by what happens in the first 48 hours after discovery. Most cyber claims that go badly are not coverage disputes — they are process failures: notice sent late (policies say “as soon as practicable” and mean hours, not weeks), forensics done by the cheapest vendor instead of the carrier's panel, costs paid from a founder's card with no ledger, and a fix executed so fast that the evidence the adjuster needs was re-imaged away. A claim is not an essay you write after the incident. It is a file you open in hour one and build in a fixed order — notice, counsel, evidence, ledger — while the fix clock runs in parallel.

The claim file, built in order

  1. The policy packet — assembled before the incident. One folder (paper and cloud): declarations page, all endorsements, the notice requirement verbatim, the panel-counsel and panel-vendor list, the broker's mobile number, the carrier's 24/7 claim line. Reviewed for twenty minutes at every renewal, because endorsements change silently. A policy nobody can find at 2am is a policy you will notice late — and late notice is the number-one reason small-team claims get reduced or denied.
  2. The first call: notice, inside the policy clock. As soon as a plausible incident is confirmed, call the broker and the carrier claim line. Notice is not a confession and does not admit the attack worked — it starts the file, gets the claim number, and unlocks the panel. Log it: date, time, who you spoke to, claim number, what was said. “We wanted to understand it better first” is how a 72-hour policy clock becomes a denial letter.
  3. Approved counsel first, then panel forensics. Engage counsel from the insurer's panel before touching systems deeply, so forensic work runs under privilege; then bring the panel incident-response firm the carrier knows and will reimburse. The invoice from the excellent firm you already like may be unreimbursed if the policy requires panel approval — ask the carrier in the same call, not after the invoice lands.
  4. Evidence preservation before any fix. Disk images of affected hosts, exports of the logs that matter (auth, EDR, VPN, email), the ransom note saved as-is, extortion communications routed through counsel, and a chain-of-custody table: what was captured, where it lives, who captured it, when, and its hash. The fastest restore in the world is still second place to a defensible picture of what happened — and the adjuster, the forensic firm, and (if it comes to it) law enforcement all read that picture.
  5. The cost ledger, opened in hour one. One sheet, one row per cost from the first hour: timestamp, category (forensics, counsel, overtime, notification mail, credit monitoring, extra infra, lost revenue), amount, receipt link, and whether the carrier pre-approved it. The ledger is the claim. Reconstructing spend from card statements in week three loses the overtime, the taxi, the night of cloud egress — and credibility with the adjuster.
  6. Notification alignment — insurer before customers. Loop the carrier before any external word; many policies require consent for public statements and approved counsel for regulator notices. The breach notification map and the claim file share a first call — make it once, to the broker, and both clocks start on the record.
  7. Business interruption and extra expense, with a baseline. Lost revenue is claimable only against a documented baseline: the last twelve months of revenue by week, the outage timeline in hours, and the mitigation costs (cloud surge, temp help, expedited shipping). Export the baseline during the incident — the billing system that proves your normal month may be the system that is down.
  8. Cooperation and subrogation duties. Do not admit liability, do not speculate in writing about cause, preserve anything an attacker touched, and follow the cooperation clause: the carrier is (financially) on your side and needs your file to be consistent with the forensic one. One founder speculation email can cost a settlement leverage nobody can buy back.
  9. The remediation story — you are writing next year's premium. The claim closes with evidence, not promises: the fix sprint's tickets, the restore-drill timestamp, MFA coverage, EDR rollout, the retest. The renewal requirements checklist is where that file gets kept warm; a claim file that ends with “here is what changed” reads as a mature insured, and renewal pricing remembers.

The five traps

Worked example: the 02:14 Saturday

An eleven-person logistics SaaS wakes to ransomware at 02:14 Saturday: files encrypted on two production hosts, a ransom note, and a founder with a credit card and good intentions. The rerun — because they had run this drill on paper — looked like: broker call at 06:00 the same morning (claim number opened), panel counsel engaged by 09:00, panel forensics imaging hosts by noon, cost ledger row one (the imaging) opened by 13:00, extortion contact routed through counsel only, customers restored from the Friday 18:00 backup by Wednesday, revenue baseline exported from the still-alive billing replica on Monday. The claim: $38k forensics and counsel, $9k notification and monitoring, $21k business interruption against a documented baseline — paid at day 34 with one adjuster question, answered from the ledger. The neighboring agency that hit the same strain fixed everything by Sunday, filed on day 30 from card statements, hired their own firm, and recovered two-thirds — the difference was not coverage. It was order of operations.

Metrics (for the claim loop itself)

From the HIVE80lab kit

Related: the data breach notification map shares this page's first call — the broker hears it before any customer does; the ransomware recovery checklist is the fix track that runs in parallel with the claim track — two tracks, one commander; and the cyber insurance requirements checklist is where the policy packet is assembled and where next year's renewal answers live.